PT-2020-10070 · Inogard+1 · Inogard Ebiz4U Activex+2
Published
2020-04-29
·
Updated
2020-05-11
·
CVE-2019-19165
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Inogard Ebiz4u ActiveX versions 1.0.5.0 and later
Description
The issue allows remote files to be downloaded and executed by setting arguments to the ActiveX method, specifically in the AxECM.cab ActiveX control. This enables an attacker to cause a file download to a Windows user's folder and execute it. The vulnerability is related to the download of code without an integrity check in the ActiveX control.
Recommendations
For Inogard Ebiz4u ActiveX versions 1.0.5.0 and later, consider disabling the AxECM.cab ActiveX control until a patch is available to prevent remote file execution. Restrict access to the ActiveX method to minimize the risk of exploitation. Avoid using the affected ActiveX control on Windows 7/8/10 systems until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Axecm.Cab Activex Control
Inogard Ebiz4U Activex
Windows