PT-2020-19805 · Raonwiz · Raonwiz K Upload

Soonchan Hwang

·

Published

2020-05-21

·

Updated

2023-05-08

·

CVE-2020-7808

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions RAONWIZ K Upload versions 2018.0.2.51 and prior
Description The issue allows an attacker to modify arguments in the update module, specifically in the web.js file, due to the lack of an integrity check during automatic update processing. This can lead to the downloading of a random DLL and its subsequent injection.
Recommendations For RAONWIZ K Upload versions 2018.0.2.51 and prior, consider disabling the automatic update feature until a patch is available to prevent potential exploitation. Restrict access to the update module, specifically the web.js file, to minimize the risk of DLL injection.

Fix

Argument Injection

Weakness Enumeration

Related Identifiers

CVE-2020-7808

Affected Products

Raonwiz K Upload