CVE-2008-4453
The GdPicture (1) Light Imaging Toolkit 4.7.1 GdPicture4S.Imaging ActiveX control (gdpicture4s.ocx) 4.7.0.1 and (2) Pro Imaging SDK 5.7.1 GdPicturePro5S.Imaging ActiveX control (gdpicturepro5s.ocx) 5.7.0.1 allows remote attackers to create, overwrite,…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 10.5%, higher than 95% of all known CVEs. Patch or mitigate before the next change window.
Description
The GdPicture (1) Light Imaging Toolkit 4.7.1 GdPicture4S.Imaging ActiveX control (gdpicture4s.ocx) 4.7.0.1 and (2) Pro Imaging SDK 5.7.1 GdPicturePro5S.Imaging ActiveX control (gdpicturepro5s.ocx) 5.7.0.1 allows remote attackers to create, overwrite, and modify arbitrary files via the SaveAsPDF method. NOTE: this issue might only be exploitable in limited environments or non-default browser settings. NOTE: this can be leveraged for remote code execution by accessing files using hcp:// URLs. NOTE: some of these details are obtained from third party information.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 10.47% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- dspicture/light imaging toolkit · dspicture/pro imaging sdk
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/31898Vendor Advisory
- http://secunia.com/advisories/31966Vendor Advisory
- http://securityreason.com/securityalert/4355
- http://www.securityfocus.com/bid/31504Exploit, Patch
- http://www.vupen.com/english/advisories/2008/2708
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45536
- https://www.exploit-db.com/exploits/6638
- http://secunia.com/advisories/31898Vendor Advisory
- http://secunia.com/advisories/31966Vendor Advisory
- http://securityreason.com/securityalert/4355
- http://www.securityfocus.com/bid/31504Exploit, Patch
- http://www.vupen.com/english/advisories/2008/2708
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45536
- https://www.exploit-db.com/exploits/6638
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.