PT-2011-4717 · Dvr · Dvr Remote Activex Control

Published

2011-11-26

·

Updated

2018-10-09

·

CVE-2011-3828

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions DVR Remote ActiveX control version 2.1.0.39
Description The issue allows remote attackers to execute arbitrary code via a crafted DVRobot.dll file in a manifest directory on a web server. This is related to the DVRemoteAx.ax component in the DVR Remote ActiveX control.
Recommendations For version 2.1.0.39, consider restricting access to the DVRemoteAx.ax component until a patch is available. As a temporary workaround, avoid using the DVR Remote ActiveX control with untrusted web servers.

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-3828

Affected Products

Dvr Remote Activex Control