SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2007-4471

Multiple unspecified vulnerabilities in the Intuit QuickBooks Online Edition ActiveX control before 10 allow remote attackers to create or overwrite arbitrary files via unspecified arguments to the (1) httpGETToFile, (2) httpPOSTFromFile, and possibly…

HIGH 9.3EPSS 5.16%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (5.16%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Multiple unspecified vulnerabilities in the Intuit QuickBooks Online Edition ActiveX control before 10 allow remote attackers to create or overwrite arbitrary files via unspecified arguments to the (1) httpGETToFile, (2) httpPOSTFromFile, and possibly other methods, probably involving path traversal vulnerabilities in exposed dangerous methods. NOTE: this can be leveraged for code execution by writing to a Startup folder.

CVSS 2.0
9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS
5.16% probability · 92th percentile
CISA KEV
Not listed
Weakness
CWE-22, CWE-264
Affected
intuit/quickbooks
Source
cret@cert.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.