CVE-2008-2511
Directory traversal vulnerability in the UmxEventCli.CachedAuditDataList.1 (aka UmxEventCliLib) ActiveX control in UmxEventCli.dll in CA Internet Security Suite 2008 allows remote attackers to create and overwrite arbitrary files via a ..
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 10.0%, higher than 95% of all known CVEs. Patch or mitigate before the next change window.
Description
Directory traversal vulnerability in the UmxEventCli.CachedAuditDataList.1 (aka UmxEventCliLib) ActiveX control in UmxEventCli.dll in CA Internet Security Suite 2008 allows remote attackers to create and overwrite arbitrary files via a .. (dot dot) in the argument to the SaveToFile method. NOTE: this can be leveraged for code execution by writing to a Startup folder. NOTE: some of these details are obtained from third party information.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 10.01% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- ca/internet security suite plus 2008
- Source
- cve@mitre.org
References
- http://retrogod.altervista.org/9sg_CA_poc.htmlExploit
- http://secunia.com/advisories/30420Vendor Advisory
- http://www.securityfocus.com/archive/1/492679/100/0/threaded
- http://www.securitytracker.com/id?1020129
- http://www.vupen.com/english/advisories/2008/1696/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42712
- https://www.exploit-db.com/exploits/5682
- http://retrogod.altervista.org/9sg_CA_poc.htmlExploit
- http://secunia.com/advisories/30420Vendor Advisory
- http://www.securityfocus.com/archive/1/492679/100/0/threaded
- http://www.securitytracker.com/id?1020129
- http://www.vupen.com/english/advisories/2008/1696/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42712
- https://www.exploit-db.com/exploits/5682
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.