PT-2018-18309 · Milestone · Milestone Xprotect Video Management

Published

1999-01-01

·

Updated

2018-06-13

·

CVE-2018-7891

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Milestone XProtect Video Management Software (Corporate, Expert, Professional+, Express+, Essential+) versions 2016 R1 (10.0.a) through 2018 R1 (12.1a)
Description: The issue concerns .NET Remoting endpoints that are vulnerable to deserialization attacks, which can result in remote code execution.
Recommendations: For versions 2016 R1 (10.0.a) through 2018 R1 (12.1a), consider disabling the .NET Remoting endpoints as a temporary workaround until a patch is available. Restrict access to these endpoints to minimize the risk of exploitation.

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-7891
DOTNETREMOTINGCHECK

Affected Products

Milestone Xprotect Video Management