CVE-2009-1092: Use After Free
Use-after-free vulnerability in the LIVEAUDIO.LiveAudioCtrl.1 ActiveX control in LIVEAU~1.OCX 7.0 for GeoVision DVR systems allows remote attackers to execute arbitrary code by calling the GetAudioPlayingTime method with certain arguments.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-1092?
CVE-2009-1092 is classified as a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2009-1092?
To fix CVE-2009-1092, users should update the LIVEAUDIO.ActiveX control to a patched version provided by GeoVision.
What types of systems are affected by CVE-2009-1092?
CVE-2009-1092 specifically affects GeoVision DVR systems that utilize version 7.0 of the LIVEAUDIO.ActiveX control.
What is the attack vector for CVE-2009-1092?
CVE-2009-1092 can be exploited remotely by calling the GetAudioPlayingTime method with malicious arguments.
Can CVE-2009-1092 be exploited without user interaction?
Yes, CVE-2009-1092 can potentially be exploited without user interaction if the target system visits a malicious webpage.