PT-2008-3414 · Cdnetworks · Neffylauncher.Dll+2

Simon Ryeo

·

Publicado

2008-04-18

·

Atualizado

2017-09-29

·

CVE-2008-1886

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions CDNetworks Nefficient Download version 1.0.5
Description The issue concerns the use of weak cryptography for a KeyCode in the NeffyLauncher ActiveX control, allowing remote attackers to bypass protection by calculating the required KeyCode. This can be exploited by arbitrary web sites hosting malicious code targeting the control.
Recommendations For version 1.0.5, consider disabling the NeffyLauncher ActiveX control until a patch is available to prevent exploitation. Restrict access to the NeffyLauncher.dll module to minimize the risk of unauthorized use. Avoid using the control on untrusted web sites to reduce the risk of hosting exploit code.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-1886

Produtos afetados

Nefficient Download
Neffylauncher Activex Control
Neffylauncher.Dll