CVE-2022-23763 Vulnerability Details

  /     /     /  

CVE-2022-23763 Metadata Quick Info

CVE Published: 28/06/2022 | CVE Updated: 03/08/2024 | CVE Year: 2022
Source: krcert | Vendor: DOUZONE BIZON Co.,Ltd | Product: NeoRS
Status : PUBLISHED

CVE-2022-23763 Description

Origin validation error vulnerability in NeoRS’s ActiveX moudle allows attackers to download and execute arbitrary files. Remote attackers can use this vulerability to encourage users to access crafted web pages, causing damage such as malicious code infections.

Metrics

CVSS Version: 3.1 | Base Score: 7.8 HIGH
Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

l➤ Exploitability Metrics:
    Attack Vector (AV)* LOCAL
    Attack Complexity (AC)* LOW
    Privileges Required (PR)* NONE
    User Interaction (UI)* REQUIRED
    Scope (S)* UNCHANGED

l➤ Impact Metrics:
    Confidentiality Impact (C)* HIGH
    Integrity Impact (I)* HIGH
    Availability Impact (A)* HIGH

Weakness Enumeration (CWE)

CWE-ID: CWE-346
CWE Name: CWE-346 Origin Validation Error
Source: DOUZONE BIZON Co.,Ltd

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).