CVE-2022-23763

Origin validation error vulnerability in NeoRS’s ActiveX moudle allows attackers to download and execute arbitrary files. Remote attackers can use this vulerability to encourage users to access crafted web pages, causing damage such as malicious code infections.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:douzone:neors:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

21 Nov 2024, 06:49

Type Values Removed Values Added
CVSS v2 : 6.8
v3 : 8.8
v2 : 6.8
v3 : 7.8
References () https://www.krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=66788 - Third Party Advisory () https://www.krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=66788 - Third Party Advisory

Information

Published : 2022-06-28 14:15

Updated : 2024-11-21 06:49


NVD link : CVE-2022-23763

Mitre link : CVE-2022-23763

CVE.ORG link : CVE-2022-23763


JSON object : View

Products Affected

microsoft

  • windows

douzone

  • neors
CWE
CWE-346

Origin Validation Error