The vulnerabilty was discovered in ActiveX module related to NeoRS remote support program. This issue allows an remote attacker to download and execute remote file. It is because of improper parameter validation of StartNeoRS function in ActiveX.
References
Link | Resource |
---|---|
https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=36367 | Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
01 Dec 2021, 20:22
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-20 | |
References | (MISC) https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=36367 - Third Party Advisory | |
CPE | cpe:2.3:a:douzone:neors:*:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* |
|
CVSS |
v2 : v3 : |
v2 : 9.3
v3 : 8.8 |
30 Nov 2021, 19:37
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2021-11-30 19:15
Updated : 2024-02-04 22:08
NVD link : CVE-2020-7880
Mitre link : CVE-2020-7880
CVE.ORG link : CVE-2020-7880
JSON object : View
Products Affected
microsoft
- windows
douzone
- neors
CWE
CWE-20
Improper Input Validation