PT-2007-4157 · H+H · Virtual Cd+1

Rgod

·

Published

2007-05-24

·

Updated

2017-10-11

·

CVE-2007-2853

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Virtual CD version 9.0.0.2
Description The issue allows remote attackers to execute arbitrary commands. This is achieved by providing a command line in the first argument to the VCDLaunchAndWait function of the VCDAPILibApi ActiveX control in vc9api.DLL.
Recommendations For Virtual CD version 9.0.0.2, consider disabling the VCDLaunchAndWait function as a temporary workaround until a patch is available. Restrict access to the vc9api.DLL module to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-2853

Affected Products

Vcdapilibapi
Virtual Cd