CVE-2008-1647
The ChilkatHttp.ChilkatHttp.1 and ChilkatHttp.ChilkatHttpRequest.1 ActiveX controls in ChilkatHttp.dll 2.4.0.0, 2.3.0.0, and earlier in ChilkatHttp ActiveX expose the unsafe SaveLastError method, which allows remote attackers to overwrite arbitrary files.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (7.01%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The ChilkatHttp.ChilkatHttp.1 and ChilkatHttp.ChilkatHttpRequest.1 ActiveX controls in ChilkatHttp.dll 2.4.0.0, 2.3.0.0, and earlier in ChilkatHttp ActiveX expose the unsafe SaveLastError method, which allows remote attackers to overwrite arbitrary files. NOTE: some of these details are obtained from third party information.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 7.01% probability · 94th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- chilkat software/chilkathttp activex
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/29581Vendor Advisory
- http://www.securityfocus.com/bid/28546Exploit
- http://www.shinnai.altervista.org/index.php?mod=02_Forum&group=Security&argument=Remote_performed_exploits&topic=1207033569.ff.phpExploit
- http://www.vupen.com/english/advisories/2008/1050/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45988
- https://www.exploit-db.com/exploits/5338
- http://secunia.com/advisories/29581Vendor Advisory
- http://www.securityfocus.com/bid/28546Exploit
- http://www.shinnai.altervista.org/index.php?mod=02_Forum&group=Security&argument=Remote_performed_exploits&topic=1207033569.ff.phpExploit
- http://www.vupen.com/english/advisories/2008/1050/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45988
- https://www.exploit-db.com/exploits/5338
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.