PT-2020-19805 · Raonwiz · Raonwiz K Upload
Soonchan Hwang
·
Published
2020-05-21
·
Updated
2023-05-08
·
CVE-2020-7808
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
RAONWIZ K Upload versions 2018.0.2.51 and prior
Description
The issue allows an attacker to modify arguments in the update module, specifically in the web.js file, due to the lack of an integrity check during automatic update processing. This can lead to the downloading of a random DLL and its subsequent injection.
Recommendations
For RAONWIZ K Upload versions 2018.0.2.51 and prior, consider disabling the automatic update feature until a patch is available to prevent potential exploitation. Restrict access to the update module, specifically the web.js file, to minimize the risk of DLL injection.
Fix
Argument Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Raonwiz K Upload