CVE Published: 06/05/2020 |
CVE Updated: 05/08/2024 |
CVE Year: 2019 Source: krcert |
Vendor: RAONwiz |
Product: Dext.ocx ActiveX Control in Dext5 Upload Status : PUBLISHED
CVE-2019-19168 Description
Dext5.ocx ActiveX 5.0.0.116 and eariler versions contain a vulnerability, which could allow remote attacker to download and execute remote arbitrary file by setting the arguments to the activex method. This can be leveraged for code execution.
Metrics
CVSS Version: 3.1 |
Base Score: 7.8 HIGH Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H