PT-2010-3192 · Gigabyte · Gigabyte Dldrv2 Activex Control

Publicado

2010-08-02

·

Atualizado

2010-08-03

·

CVE-2010-1517

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions GIGABYTE Dldrv2 ActiveX control version 1.4.206.11
Description The issue allows remote attackers to download and execute arbitrary programs onto a client system. This can be achieved through vectors involving the dl method or the SetDLInfo method in conjunction with the Bdl method.
Recommendations For GIGABYTE Dldrv2 ActiveX control version 1.4.206.11, consider disabling the dl and SetDLInfo methods as a temporary workaround until a patch is available. Restrict access to the Bdl method to minimize the risk of exploitation.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-1517

Produtos afetados

Gigabyte Dldrv2 Activex Control