PT-2008-5593 · Chilkat · Chilkat Xml Chilkatutil.Ckdata.1 Activex Control
Shinnai
·
Published
2008-09-30
·
Updated
2024-02-14
·
CVE-2008-4343
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Chilkat XML ChilkatUtil.CkData.1 ActiveX control versions 3.0.3.0 and earlier
Description:
The issue allows remote attackers to create, overwrite, and modify arbitrary files for execution via calls to specific methods. This can potentially be leveraged for remote code execution by accessing files using hcp:// URLs. The exploitability might be limited to certain environments or non-default browser settings.
Recommendations:
For versions 3.0.3.0 and earlier, consider disabling the SaveToFile, SaveToTempFile, or AppendBinary methods as a temporary workaround until a patch is available. Restrict access to files using hcp:// URLs to minimize the risk of exploitation.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Chilkat Xml Chilkatutil.Ckdata.1 Activex Control