First published: Wed May 06 2020(Updated: )
Dext5.ocx ActiveX 5.0.0.116 and eariler versions contain a vulnerability, which could allow remote attacker to download arbitrary file by setting the arguments to the activex method. This can be leveraged for code execution.
Credit: vuln@krcert.or.kr
Affected Software | Affected Version | How to fix |
---|---|---|
Raonwiz Dext5 | =2.7 | |
Microsoft Activex | <5.0.0.117 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-19169 is a vulnerability in Dext5.ocx ActiveX 5.0.0.116 and earlier versions that allows a remote attacker to download an arbitrary file.
The vulnerability can be exploited by setting the arguments to the ActiveX method, allowing the attacker to download arbitrary files and potentially execute code.
CVE-2019-19169 has a severity rating of critical, with a CVSS score of 9.8.
Dext5.ocx ActiveX 5.0.0.116 and earlier versions are affected by CVE-2019-19169.
To fix CVE-2019-19169, it is recommended to update to a version of Dext5.ocx ActiveX that is not affected by the vulnerability.