PT-2008-3161 · Lead Technologies · Leadtools Multimedia Toolkit

Published

2008-04-01

·

Updated

2017-08-08

·

CVE-2008-1605

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions LEADTOOLS Multimedia Toolkit versions 15.1.0.17 and earlier
Description The issue allows attackers to overwrite arbitrary files via the SaveSettingsToFile method in the ltmmCaptureCtrl, ltmmConvertCtrl, and ltmmPlayCtrl ActiveX controls.
Recommendations For versions 15.1.0.17 and earlier, consider disabling the SaveSettingsToFile method until a patch is available to prevent arbitrary file overwrites. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-1605

Affected Products

Leadtools Multimedia Toolkit