CVE-2020-7874
Last modified
CVE-2020-7874 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Download of code without integrity check vulnerability in NEXACRO14 Runtime ActiveX control of tobesoft Co., Ltd allows the attacker to cause an arbitrary file download and execution. This vulnerability is due to incomplete validation of file download URL or file extension.. EPSS estimates a 0.56% chance of exploitation in the next 30 days.
Description
Download of code without integrity check vulnerability in NEXACRO14 Runtime ActiveX control of tobesoft Co., Ltd allows the attacker to cause an arbitrary file download and execution. This vulnerability is due to incomplete validation of file download URL or file extension.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Tobesoft | Nexacro | >= 14.0.0.0, < 14.0.1.3600 |
References
- https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=36235Third Party Advisory
- https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=36235Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-7874?
How severe is CVE-2020-7874?
How do I fix CVE-2020-7874?
Are you affected by CVE-2020-7874?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
