CVE-2008-4343
Last modified
CVE-2008-4343 is a vulnerability of currently unknown severity. The Chilkat XML ChilkatUtil.CkData.1 ActiveX control (ChilkatUtil.dll) 3.0.3.0 and earlier allows remote attackers to create, overwrite, and modify arbitrary files for execution via a call to the (1) SaveToFile, (2) SaveToTempFile, or (3) AppendBinary method. NOTE: this issue might only be exploitable in limited environments or non-default browser settings. EPSS estimates a 8.68% chance of exploitation in the next 30 days.
Description
The Chilkat XML ChilkatUtil.CkData.1 ActiveX control (ChilkatUtil.dll) 3.0.3.0 and earlier allows remote attackers to create, overwrite, and modify arbitrary files for execution via a call to the (1) SaveToFile, (2) SaveToTempFile, or (3) AppendBinary method. NOTE: this issue might only be exploitable in limited environments or non-default browser settings. NOTE: this can be leveraged for remote code execution by accessing files using hcp:// URLs.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Chilkat Software | Chilkat Xml Activex Control | <= 3.0.3.0 |
References
- http://secunia.com/advisories/31951Vendor Advisory
- http://www.shinnai.net/xplits/TXT_rNowA1916DKFNUF48NySExploit, URL Repurposed
- http://secunia.com/advisories/31951Vendor Advisory
- http://www.shinnai.net/xplits/TXT_rNowA1916DKFNUF48NySExploit, URL Repurposed
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-4343?
How severe is CVE-2008-4343?
How do I fix CVE-2008-4343?
Are you affected by CVE-2008-4343?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
