PT-2020-19800 · Microsoft+1 · Windows+1

Donghyun

+1

·

Published

2020-05-07

·

Updated

2020-08-06

·

CVE-2020-7803

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zoneplayer versions 2.0.1.3 and prior versions Zoneplayer version 2.0.1.4
Description The issue allows an attacker to cause arbitrary code execution due to a file download vulnerability in the ZInsX.ocx ActiveX Control of Zoneplayer on Windows.
Recommendations For Zoneplayer versions 2.0.1.3 and prior versions, update to a version later than 2.0.1.3 to resolve the issue. For Zoneplayer version 2.0.1.4, update to a version later than 2.0.1.4 to resolve the issue. As a temporary workaround, consider disabling the ZInsX.ocx ActiveX Control until a patch is available.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-7803

Affected Products

Windows
Zoneplayer