First published: Tue Jun 30 2020(Updated: )
CyMiInstaller322 ActiveX which runs MIPLATFORM downloads files required to run applications. A vulnerability in downloading files by CyMiInstaller322 ActiveX caused by an attacker to download randomly generated DLL files and MIPLATFORM to load those DLLs due to insufficient verification.
Credit: vuln@krcert.or.kr
Affected Software | Affected Version | How to fix |
---|---|---|
Cymiinstaller322 Activex Project Cymiinstaller322 Activex | <=2016.5.26.1 | |
Microsoft Windows 10 | ||
Microsoft Windows 7 | ||
Microsoft Windows 8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2019-19161.
The severity of CVE-2019-19161 is high with a CVSS score of 7.2 (out of 10).
The Cymiinstaller322 ActiveX version 2016.5.26.1 is affected by CVE-2019-19161.
CVE-2019-19161 allows an attacker to download randomly generated DLL files and load them using MIPLATFORM, leading to potential code execution or denial of service.
No, Microsoft Windows 10, Windows 7, and Windows 8 are not directly vulnerable to CVE-2019-19161.