First published: Tue May 19 2020(Updated: )
In RAONWIZ K Upload v2018.0.2.51 and prior, automatic update processing without integrity check on update module(web.js) allows an attacker to modify arguments which causes downloading a random DLL and injection on it.
Credit: vuln@krcert.or.kr
Affected Software | Affected Version | How to fix |
---|---|---|
Raonwiz Raon K Upload | <=2018.0.2.51 | |
Microsoft Windows 10 | ||
Microsoft Windows 7 | ||
Microsoft Windows 8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-7808 is critical with a CVSS score of 9.8.
RAONWIZ K Upload v2018.0.2.51 and prior versions are affected by CVE-2020-7808.
An attacker can exploit CVE-2020-7808 by modifying arguments during the automatic update process, which causes downloading a random DLL and injection on it.
No, Microsoft Windows 10 is not vulnerable to CVE-2020-7808.
You can find more information about CVE-2020-7808 at the following link: [CVE-2020-7808](https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=35424)