HIGH · 9.3

CVE-2014-1861

The client in Jetro COCKPIT Secure Browsing (JCSB) 4.3.1 and 4.3.3 does not validate the FileName element in an RDP_FILE_TRANSFER document, which allows remote JCSB servers to execute arbitrary progra...

Vulnerability Description

The client in Jetro COCKPIT Secure Browsing (JCSB) 4.3.1 and 4.3.3 does not validate the FileName element in an RDP_FILE_TRANSFER document, which allows remote JCSB servers to execute arbitrary programs by providing a .EXE extension.

CVSS Score

9.3

HIGH

AV:N/AC:M/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
JetroplatformsJetro Cockpit Secure Browsing4.3.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2014-1861?

CVE-2014-1861 is a vulnerability with a CVSS score of 9.3 (HIGH). The client in Jetro COCKPIT Secure Browsing (JCSB) 4.3.1 and 4.3.3 does not validate the FileName element in an RDP_FILE_TRANSFER document, which allows remote JCSB servers to execute arbitrary progra...

How severe is CVE-2014-1861?

CVE-2014-1861 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2014-1861?

Check the references section above for vendor advisories and patch information. Affected products include: Jetroplatforms Jetro Cockpit Secure Browsing.