First published: Thu Sep 09 2021(Updated: )
An arbitrary file download and execution vulnerability was found in the HShell.dll of handysoft Co., Ltd groupware ActiveX module. This issue is due to missing support for integrity check of download URL or downloaded file hash.
Credit: vuln@krcert.or.kr
Affected Software | Affected Version | How to fix |
---|---|---|
Handysoft Hshell | =1.7.4.5 | |
Handysoft Hshell | =2.0.3.5 | |
Handysoft Hshell | =4.0.1.6 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-26608 is critical with a CVSS score of 9.8.
CVE-2021-26608 is an arbitrary file download and execution vulnerability in the HShell.dll of handysoft Co., Ltd groupware ActiveX module. This vulnerability allows an attacker to download and execute arbitrary files due to missing support for integrity check of download URL or downloaded file hash.
The following versions of Handysoft Hshell are affected by CVE-2021-26608: 1.7.4.5, 2.0.3.5, and 4.0.1.6.
No, Microsoft Windows is not vulnerable to CVE-2021-26608.
You can find more information about CVE-2021-26608 at the following link: https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=36239