Tobesoft XPlatform v9.1, 9.2.0, 9.2.1 and 9.2.2 have a vulnerability that can load unauthorized DLL files. It allows attacker to cause remote code execution.
The product downloads source code or an executable from a remote location and executes the code without sufficiently verifying the origin and integrity of the code.
Link | Tags |
---|---|
http://support.tobesoft.co.kr/Support/index.html | vendor advisory |
https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=35357 | third party advisory |