The cross-browser document creation component produced by Digitware System Integration Corporation has a Remote Code Execution vulnerability. If a user visits a malicious website while the component is active, remote attackers can cause the system to download and execute arbitrary programs.
Solution:
The product downloads source code or an executable from a remote location and executes the code without sufficiently verifying the origin and integrity of the code.
Link | Tags |
---|---|
https://www.twcert.org.tw/tw/cp-132-10241-2ec07-1.html | third party advisory |
https://www.twcert.org.tw/en/cp-139-10242-5ab42-2.html | third party advisory |