PT-2007-3300 · Skc · Skcrypax Activex Control Module
Publicado
2007-04-11
·
Atualizado
2008-11-13
·
CVE-2007-1955
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
SKCrypAX ActiveX control module version 5.4.1.2
Description
The issue allows remote attackers to execute arbitrary code via a long string in unspecified arguments to the (1) DownloadCert, (2) DecryptFileByKey, and (3) EncryptFileByKey functions.
Recommendations
For SKCrypAX ActiveX control module version 5.4.1.2, consider disabling the
DownloadCert(), DecryptFileByKey(), and EncryptFileByKey() functions as a temporary workaround until a patch is available. Restrict access to these functions to minimize the risk of exploitation.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Skcrypax Activex Control Module