PT-2018-18309 · Milestone · Milestone Xprotect Video Management
Published
1999-01-01
·
Updated
2018-06-13
·
CVE-2018-7891
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Milestone XProtect Video Management Software (Corporate, Expert, Professional+, Express+, Essential+) versions 2016 R1 (10.0.a) through 2018 R1 (12.1a)
Description:
The issue concerns .NET Remoting endpoints that are vulnerable to deserialization attacks, which can result in remote code execution.
Recommendations:
For versions 2016 R1 (10.0.a) through 2018 R1 (12.1a), consider disabling the .NET Remoting endpoints as a temporary workaround until a patch is available. Restrict access to these endpoints to minimize the risk of exploitation.
Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Milestone Xprotect Video Management