PT-2007-3300 · Skc · Skcrypax Activex Control Module
Published
2007-04-11
·
Updated
2008-11-13
·
CVE-2007-1955
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
SKCrypAX ActiveX control module version 5.4.1.2
Description
The issue allows remote attackers to execute arbitrary code via a long string in unspecified arguments to the (1) DownloadCert, (2) DecryptFileByKey, and (3) EncryptFileByKey functions.
Recommendations
For SKCrypAX ActiveX control module version 5.4.1.2, consider disabling the
DownloadCert(), DecryptFileByKey(), and EncryptFileByKey() functions as a temporary workaround until a patch is available. Restrict access to these functions to minimize the risk of exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Skcrypax Activex Control Module