CVE-2008-4342
NuMedia Soft NMS DVD Burning SDK Activex NMSDVDX.DVDEngineX.1 ActiveX control (NMSDVDX.dll) 1.013C and earlier, as used in CDBurnerXP 4.2.1.976, BurnAware 2.1.3, Blaze Media Pro 8.02 Special Edition, and possibly other products, allows remote attackers…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 17.2%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
NuMedia Soft NMS DVD Burning SDK Activex NMSDVDX.DVDEngineX.1 ActiveX control (NMSDVDX.dll) 1.013C and earlier, as used in CDBurnerXP 4.2.1.976, BurnAware 2.1.3, Blaze Media Pro 8.02 Special Edition, and possibly other products, allows remote attackers to overwrite and create arbitrary files via calls to the EnableLog and LogMessage methods. NOTE: this issue might only be exploitable in limited environments or non-default browser settings. NOTE: some of these details are obtained from third party information. NOTE: this can be leveraged for remote code execution by accessing files using hcp:// URLs.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 17.20% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- burnaware technologies/burnaware · impressum/cdburnerxp · numedia soft/numedia dvd burning sdk
- Source
- cve@mitre.org
References
- http://retrogod.altervista.org/9sg_numedia_xpl.htmlExploit
- http://secunia.com/advisories/31936Vendor Advisory
- http://secunia.com/advisories/31949Vendor Advisory
- http://secunia.com/advisories/31950Vendor Advisory
- http://secunia.com/advisories/32455Vendor Advisory
- http://www.securityfocus.com/archive/1/497831/100/0/threaded
- http://www.securityfocus.com/bid/31374Exploit
- http://www.shinnai.net/xplits/TXT_TrWE9AJA8nQpuFsnxBcqExploit, URL Repurposed
- http://www.vupen.com/english/advisories/2008/2663Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45330
- https://www.exploit-db.com/exploits/6491
- http://retrogod.altervista.org/9sg_numedia_xpl.htmlExploit
- http://secunia.com/advisories/31936Vendor Advisory
- http://secunia.com/advisories/31949Vendor Advisory
- http://secunia.com/advisories/31950Vendor Advisory
- http://secunia.com/advisories/32455Vendor Advisory
- http://www.securityfocus.com/archive/1/497831/100/0/threaded
- http://www.securityfocus.com/bid/31374Exploit
- http://www.shinnai.net/xplits/TXT_TrWE9AJA8nQpuFsnxBcqExploit, URL Repurposed
- http://www.vupen.com/english/advisories/2008/2663Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45330
- https://www.exploit-db.com/exploits/6491
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.