CVE-2008-4342
Last modified
CVE-2008-4342 is a vulnerability of currently unknown severity. NuMedia Soft NMS DVD Burning SDK Activex NMSDVDX.DVDEngineX.1 ActiveX control (NMSDVDX.dll) 1.013C and earlier, as used in CDBurnerXP 4.2.1.976, BurnAware 2.1.3, Blaze Media Pro 8.02 Special Edition, and possibly other products, allows remote attackers to overwrite and create arbitrary files via calls to the EnableLog and LogMessage methods. NOTE: this issue might only be exploitable in limited environments or non-default browser settings. EPSS estimates a 17.20% chance of exploitation in the next 30 days.
Description
NuMedia Soft NMS DVD Burning SDK Activex NMSDVDX.DVDEngineX.1 ActiveX control (NMSDVDX.dll) 1.013C and earlier, as used in CDBurnerXP 4.2.1.976, BurnAware 2.1.3, Blaze Media Pro 8.02 Special Edition, and possibly other products, allows remote attackers to overwrite and create arbitrary files via calls to the EnableLog and LogMessage methods. NOTE: this issue might only be exploitable in limited environments or non-default browser settings. NOTE: some of these details are obtained from third party information. NOTE: this can be leveraged for remote code execution by accessing files using hcp:// URLs.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Burnaware Technologies | Burnaware | 2.1.3 | Unknown |
| Impressum | Cdburnerxp | 4.2.1.976 | — |
| Numedia Soft | Numedia Dvd Burning Sdk | 1.008 | — |
References
- http://secunia.com/advisories/31936Vendor Advisory
- http://secunia.com/advisories/31949Vendor Advisory
- http://secunia.com/advisories/31950Vendor Advisory
- http://secunia.com/advisories/32455Vendor Advisory
- http://www.shinnai.net/xplits/TXT_TrWE9AJA8nQpuFsnxBcqExploit, URL Repurposed
- http://www.vupen.com/english/advisories/2008/2663Vendor Advisory
- http://secunia.com/advisories/31936Vendor Advisory
- http://secunia.com/advisories/31949Vendor Advisory
- http://secunia.com/advisories/31950Vendor Advisory
- http://secunia.com/advisories/32455Vendor Advisory
- http://www.shinnai.net/xplits/TXT_TrWE9AJA8nQpuFsnxBcqExploit, URL Repurposed
- http://www.vupen.com/english/advisories/2008/2663Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-4342?
How severe is CVE-2008-4342?
How do I fix CVE-2008-4342?
Are you affected by CVE-2008-4342?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
