CVE-2020-7808: RAONWIZ Inc K Upload, arguments modiffication via missing support for integrity check vulnerability
Published May 21, 2020
·Updated
In RAONWIZ K Upload v2018.0.2.51 and prior, automatic update processing without integrity check on update module(web.js) allows an attacker to modify arguments which causes downloading a random DLL and injection on it.
Affected Software
4 affected components
Raonwiz RAON K Upload<=2018.0.2.51
Microsoft Windows 10
Microsoft Windows 7
Microsoft Windows 8
Event History
May 19, 2020
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-7808?
The severity of CVE-2020-7808 is critical with a CVSS score of 9.8.
2
What software versions are affected by CVE-2020-7808?
RAONWIZ K Upload v2018.0.2.51 and prior versions are affected by CVE-2020-7808.
3
How can an attacker exploit CVE-2020-7808?
An attacker can exploit CVE-2020-7808 by modifying arguments during the automatic update process, which causes downloading a random DLL and injection on it.
4
Is Microsoft Windows 10 vulnerable to CVE-2020-7808?
No, Microsoft Windows 10 is not vulnerable to CVE-2020-7808.
5
Where can I find more information about CVE-2020-7808?
You can find more information about CVE-2020-7808 at the following link: [CVE-2020-7808](https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=35424)