CVE-2020-7880

The vulnerabilty was discovered in ActiveX module related to NeoRS remote support program. This issue allows an remote attacker to download and execute remote file. It is because of improper parameter validation of StartNeoRS function in ActiveX.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:douzone:neors:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

01 Dec 2021, 20:22

Type Values Removed Values Added
References (MISC) https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=36367 - (MISC) https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=36367 - Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : 9.3
v3 : 8.8
CWE CWE-20
CPE cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:a:douzone:neors:*:*:*:*:*:*:*:*

30 Nov 2021, 19:37

Type Values Removed Values Added
New CVE

Information

Published : 2021-11-30 19:15

Updated : 2023-12-10 14:09


NVD link : CVE-2020-7880

Mitre link : CVE-2020-7880

CVE.ORG link : CVE-2020-7880


JSON object : View

Products Affected

douzone

  • neors

microsoft

  • windows
CWE
CWE-20

Improper Input Validation