Dext5.ocx ActiveX 5.0.0.116 and eariler versions contain a vulnerability, which could allow remote attacker to download and execute remote arbitrary file by setting the arguments to the activex method. This can be leveraged for code execution.
Link | Tags |
---|---|
http://www.dext5.com/page/support/notice_view.aspx?pSeq=26 | vendor advisory |
https://www.krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=35352 | third party advisory |