CVE-2019-19165

AxECM.cab(ActiveX Control) in Inogard Ebiz4u contains a vulnerability that could allow remote files to be downloaded and executed by setting arguments to the activeX method. Download of Code Without Integrity Check vulnerability in ActiveX control of Inogard Co,,LTD Ebiz4u ActiveX of Inogard Co,,LTD(AxECM.cab) allows ATTACKER to cause a file download to Windows user's folder and execute. This issue affects: Inogard Co,,LTD Ebiz4u ActiveX of Inogard Co,,LTD(AxECM.cab) version 1.0.5.0 and later versions on windows 7/8/10.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:inogard:activex:*:*:*:*:*:*:*:*
OR cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_7:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_8:-:*:*:*:*:*:*:*

History

21 Nov 2024, 04:34

Type Values Removed Values Added
References () http://www.ebiz4u.co.kr/home.do - Vendor Advisory () http://www.ebiz4u.co.kr/home.do - Vendor Advisory
References () https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=35348 - Third Party Advisory () https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=35348 - Third Party Advisory

Information

Published : 2020-04-29 16:15

Updated : 2024-11-21 04:34


NVD link : CVE-2019-19165

Mitre link : CVE-2019-19165

CVE.ORG link : CVE-2019-19165


JSON object : View

Products Affected

microsoft

  • windows_10
  • windows_8
  • windows_7

inogard

  • activex
CWE
CWE-494

Download of Code Without Integrity Check