CVE-2021-26626
Last modified
CVE-2021-26626 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Improper input validation vulnerability in XPLATFORM's execBrowser method can cause execute arbitrary commands. IF the second parameter value of the execBrowser function is ‘default’, the first parameter value could be passed to the ShellExecuteW API. EPSS estimates a 1.17% chance of exploitation in the next 30 days.
Description
Improper input validation vulnerability in XPLATFORM's execBrowser method can cause execute arbitrary commands. IF the second parameter value of the execBrowser function is ‘default’, the first parameter value could be passed to the ShellExecuteW API. The passed parameter is an arbitrary code to be executed. Remote attackers can use this vulnerability to execute arbitrary remote code.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Tobesoft | Xplatform | < 9.2.2.280 |
References
- https://www.krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=66662Third Party Advisory
- https://www.krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=66662Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-26626?
How severe is CVE-2021-26626?
How do I fix CVE-2021-26626?
Are you affected by CVE-2021-26626?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
