PT-2020-10074 · Dext5.Ocx · Dext5.Ocx

Published

2020-05-06

·

Updated

2020-05-19

·

CVE-2019-19169

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dext5.ocx ActiveX versions 5.0.0.116 and earlier
Description The issue allows a remote attacker to download arbitrary files by setting specific arguments to the ActiveX method, which can be leveraged for code execution.
Recommendations For versions 5.0.0.116 and earlier, consider disabling the vulnerable ActiveX method until a patch is available. Restrict access to the Dext5.ocx ActiveX to minimize the risk of exploitation. Avoid using the vulnerable ActiveX method in affected applications until the issue is resolved.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2019-19169

Affected Products

Dext5.Ocx