PT-2007-3300 · Skc · Skcrypax Activex Control Module

Published

2007-04-11

·

Updated

2008-11-13

·

CVE-2007-1955

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SKCrypAX ActiveX control module version 5.4.1.2
Description The issue allows remote attackers to execute arbitrary code via a long string in unspecified arguments to the (1) DownloadCert, (2) DecryptFileByKey, and (3) EncryptFileByKey functions.
Recommendations For SKCrypAX ActiveX control module version 5.4.1.2, consider disabling the DownloadCert(), DecryptFileByKey(), and EncryptFileByKey() functions as a temporary workaround until a patch is available. Restrict access to these functions to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-1955

Affected Products

Skcrypax Activex Control Module