PT-2009-4150 · Cyclomedia · Cyclomedia Cycloscopelite

Published

2009-05-18

·

Updated

2009-05-19

·

CVE-2009-1666

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: CycloMedia CycloScopeLite version 2.50.3.0
Description: The issue is related to multiple unspecified vulnerabilities that allow remote attackers to execute arbitrary code. This is achieved via the ReturnConnection method in several DLL files, including CM ADOConnection.dll, CM AddressInfoDBC.dll, and CM RecordingLocationDBC.dll. The vulnerabilities are related to improper dereferencing.
Recommendations: For CycloMedia CycloScopeLite version 2.50.3.0, consider restricting access to the ReturnConnection method in the affected DLL files until a patch is available. As a temporary workaround, disabling the ReturnConnection method could help minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2009-1666

Affected Products

Cyclomedia Cycloscopelite