PT-2009-2635 · Uusee · Uusee Uuupgrade
Published
2009-09-08
·
Updated
2017-08-17
·
CVE-2008-7168
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
UUSee UUUpgrade version 3.0.2.12
Description
The issue is related to an insecure method in the UUSee UUUpgrade ActiveX control. This allows remote attackers to force the download and overwrite of arbitrary files via crafted arguments to the
Update method. The issue has been exploited in the wild.Recommendations
For version 3.0.2.12, consider disabling the
Update method in the UUUpgrade ActiveX control until a patch is available. Restrict access to the UUUpgrade.ocx file to minimize the risk of exploitation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Uusee Uuupgrade