PT-2009-2635 · Uusee · Uusee Uuupgrade

Published

2009-09-08

·

Updated

2017-08-17

·

CVE-2008-7168

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions UUSee UUUpgrade version 3.0.2.12
Description The issue is related to an insecure method in the UUSee UUUpgrade ActiveX control. This allows remote attackers to force the download and overwrite of arbitrary files via crafted arguments to the Update method. The issue has been exploited in the wild.
Recommendations For version 3.0.2.12, consider disabling the Update method in the UUUpgrade ActiveX control until a patch is available. Restrict access to the UUUpgrade.ocx file to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2008-7168

Affected Products

Uusee Uuupgrade