VulnerabilityModified
CVE-2009-0811
Insecure method vulnerability in the SopCast SopCore ActiveX control in sopocx.ocx 3.0.3.501 allows remote attackers to execute arbitrary programs via an executable file name in the argument to the SetExternalPlayer method.
HIGH 9.3EPSS 5.54%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.54%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Insecure method vulnerability in the SopCast SopCore ActiveX control in sopocx.ocx 3.0.3.501 allows remote attackers to execute arbitrary programs via an executable file name in the argument to the SetExternalPlayer method.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 5.54% probability · 92th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- sopcast/sopcore activex control
- Source
- cve@mitre.org
References
- http://retrogod.altervista.org/9sg_sopcastia.html
- http://www.securityfocus.com/archive/1/501252/100/0/threaded
- http://www.securityfocus.com/bid/33920Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/48955
- http://retrogod.altervista.org/9sg_sopcastia.html
- http://www.securityfocus.com/archive/1/501252/100/0/threaded
- http://www.securityfocus.com/bid/33920Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/48955
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.