Nexacro14/17 ExtCommonApiV13 Library under 2019.9.6 version contain a vulnerability that could allow remote attacker to execute arbitrary code by setting the arguments to the vulnerable API. This can be leveraged for code execution by rebooting the victim’s PC
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
http://support.tobesoft.co.kr/Support/index.html | third party advisory |
https://www.krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=35491 | third party advisory |