First published: Wed Jun 23 2004(Updated: )
acpRunner ActiveX 1.2.5.0 allows remote attackers to execute arbitrary code via the (1) DownLoadURL, (2) SaveFilePath, and (3) Download ActiveX methods.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Acprunner | =1.2.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0586 is considered a critical vulnerability as it allows remote attackers to execute arbitrary code.
To fix CVE-2004-0586, upgrade to a patched version of the acpRunner ActiveX control that resolves this vulnerability.
CVE-2004-0586 affects users of acpRunner ActiveX version 1.2.5.0 from IBM.
CVE-2004-0586 can be exploited through the DownLoadURL, SaveFilePath, and Download methods.
A temporary workaround for CVE-2004-0586 is to disable the acpRunner ActiveX control in your browser settings.