CVE-2019-19168: Critical severity dext5 vulnerability
Dext5.ocx ActiveX 5.0.0.116 and eariler versions contain a vulnerability, which could allow remote attacker to download and execute remote arbitrary file by setting the arguments to the activex method. This can be leveraged for code execution.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-19168?
CVE-2019-19168 is a vulnerability in Dext5.ocx ActiveX 5.0.0.116 and earlier versions that allows remote attackers to download and execute remote arbitrary files.
What is the severity of CVE-2019-19168?
The severity of CVE-2019-19168 is critical with a CVSS score of 9.8.
Which software versions are affected by CVE-2019-19168?
Dext5.ocx ActiveX version 5.0.0.116 and earlier versions are affected.
How can an attacker exploit CVE-2019-19168?
An attacker can exploit CVE-2019-19168 by setting the arguments to the ActiveX method, allowing them to download and execute remote arbitrary files.
How can I mitigate the risk of CVE-2019-19168?
To mitigate the risk of CVE-2019-19168, ensure that you update to a version higher than 5.0.0.116 of Dext5.ocx ActiveX.