CVE-2009-0389
Last modified
CVE-2009-0389 is a vulnerability of currently unknown severity. Multiple insecure method vulnerabilities in the Web On Windows (WOW) ActiveX control in WOW ActiveX 2 allow remote attackers to (1) create and overwrite arbitrary files via the WriteIniFileString method, (2) execute arbitrary programs via the ShellExecute method, (3) read from the registry via unspecified vectors, and (4) write to the registry via unspecified vectors. NOTE: vectors 1 and 2 can be used together to execute arbitrary code.. EPSS estimates a 8.79% chance of exploitation in the next 30 days.
Description
Multiple insecure method vulnerabilities in the Web On Windows (WOW) ActiveX control in WOW ActiveX 2 allow remote attackers to (1) create and overwrite arbitrary files via the WriteIniFileString method, (2) execute arbitrary programs via the ShellExecute method, (3) read from the registry via unspecified vectors, and (4) write to the registry via unspecified vectors. NOTE: vectors 1 and 2 can be used together to execute arbitrary code.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Eztools-Software | Web On Windows Activex | 2 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-0389?
How severe is CVE-2009-0389?
How do I fix CVE-2009-0389?
Are you affected by CVE-2009-0389?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
