VulnerabilityModified
CVE-2008-0237
The Microsoft Rich Textbox ActiveX Control (RICHTX32.OCX) 6.1.97.82 allows remote attackers to execute arbitrary commands by invoking the insecure SaveFile method.
MEDIUM 6.8EPSS 20.5%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 20.5%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
The Microsoft Rich Textbox ActiveX Control (RICHTX32.OCX) 6.1.97.82 allows remote attackers to execute arbitrary commands by invoking the insecure SaveFile method.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 20.47% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- microsoft/rich textbox control
- Source
- cve@mitre.org
References
- http://shinnai.altervista.org/exploits/txt/TXT_DZVN8CwCha0I2fI3NeEs.htmlExploit
- http://www.securityfocus.com/bid/27201Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39557
- https://www.exploit-db.com/exploits/4874
- http://shinnai.altervista.org/exploits/txt/TXT_DZVN8CwCha0I2fI3NeEs.htmlExploit
- http://www.securityfocus.com/bid/27201Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39557
- https://www.exploit-db.com/exploits/4874
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.