PT-2021-20218 · Naver · Naver Toolbar

Powerprove

·

Published

2021-07-19

·

Updated

2022-10-27

·

CVE-2021-33592

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NAVER Toolbar versions prior to 4.0.30.323
Description The issue allows remote attackers to execute arbitrary code via a crafted upgrade.xml file. Special characters in the filename parameter can bypass the code signing check function.
Recommendations For versions prior to 4.0.30.323, update to version 4.0.30.323 or later to resolve the issue. As a temporary workaround, consider restricting the use of the filename parameter in the upgrade.xml file to minimize the risk of exploitation.

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2021-33592

Affected Products

Naver Toolbar