CVE-2020-7875: RAONWIZ DEXT5 Upload ActiveX remote file execution vulnerability
Published Oct 28, 2021
·Updated
DEXT5 Upload 5.0.0.117 and earlier versions contain a vulnerability, which could allow remote attacker to download and execute remote file by setting the argument, variable in the activeX module. This can be leveraged for code execution.
Affected Software
2 affected components
DEXT5 DEXT5Upload<=5.0.0.117
Microsoft Windows
Event History
Oct 28, 2021
CVE Published
via MITRE·03:28 PM
Data Sourced
via MITRE·03:28 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-7875?
CVE-2020-7875 has a high severity due to its potential to allow remote code execution.
2
How do I fix CVE-2020-7875?
To mitigate CVE-2020-7875, upgrade DEXT5 Upload to version 5.0.0.118 or later.
3
Who is affected by CVE-2020-7875?
CVE-2020-7875 affects DEXT5 Upload versions 5.0.0.117 and earlier.
4
What type of attack does CVE-2020-7875 allow?
CVE-2020-7875 allows remote attackers to download and execute arbitrary files.
5
What platforms are affected by CVE-2020-7875?
CVE-2020-7875 affects the DEXT5 Upload application running on Microsoft Windows.