VulnerabilityModified
CVE-2008-3156
The ActiveScan ActiveX Control (as2guiie.dll) in Panda ActiveScan before 1.02.00 allows remote attackers to download and execute arbitrary cabinet (CAB) files via unspecified URLs passed to the Update method.
HIGH 9.3EPSS 4.07%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.07%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The ActiveScan ActiveX Control (as2guiie.dll) in Panda ActiveScan before 1.02.00 allows remote attackers to download and execute arbitrary cabinet (CAB) files via unspecified URLs passed to the Update method.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 4.07% probability · 90th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- panda/panda activescan
- Source
- cve@mitre.org
References
- http://karol.wiesek.pl/files/panda.tgzExploit
- http://lists.grok.org.uk/pipermail/full-disclosure/2008-July/063061.html
- http://lists.grok.org.uk/pipermail/full-disclosure/2008-July/063068.html
- http://secunia.com/advisories/30841Vendor Advisory
- http://www.securityfocus.com/bid/30086
- http://www.securitytracker.com/id?1020432
- http://www.vupen.com/english/advisories/2008/2008/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43587
- https://www.exploit-db.com/exploits/6004
- http://karol.wiesek.pl/files/panda.tgzExploit
- http://lists.grok.org.uk/pipermail/full-disclosure/2008-July/063061.html
- http://lists.grok.org.uk/pipermail/full-disclosure/2008-July/063068.html
- http://secunia.com/advisories/30841Vendor Advisory
- http://www.securityfocus.com/bid/30086
- http://www.securitytracker.com/id?1020432
- http://www.vupen.com/english/advisories/2008/2008/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43587
- https://www.exploit-db.com/exploits/6004
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.