CVE-2008-1886
The NeffyLauncher 1.0.5 ActiveX control (NeffyLauncher.dll) in CDNetworks Nefficient Download uses weak cryptography for a KeyCode that blocks unauthorized use of the control, which allows remote attackers to bypass this protection mechanism by…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (6.66%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The NeffyLauncher 1.0.5 ActiveX control (NeffyLauncher.dll) in CDNetworks Nefficient Download uses weak cryptography for a KeyCode that blocks unauthorized use of the control, which allows remote attackers to bypass this protection mechanism by calculating the required KeyCode. NOTE: this can be used by arbitrary web sites to host exploit code that targets this control.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 6.66% probability · 93th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-310
- Affected
- cdnetworks/download client
- Source
- cve@mitre.org
References
- http://seclists.org/bugtraq/2008/Apr/0065.html
- http://www.securityfocus.com/bid/28666
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41933
- https://www.exploit-db.com/exploits/5397
- http://seclists.org/bugtraq/2008/Apr/0065.html
- http://www.securityfocus.com/bid/28666
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41933
- https://www.exploit-db.com/exploits/5397
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.