HIGH · 9.3

CVE-2014-2956

ScriptHelperApi in the AVG ScriptHelper ActiveX control in ScriptHelper.exe in AVG Secure Search toolbar before 18.1.7.598 and AVG Safeguard before 18.1.7.644 does not implement domain-based access co...

Vulnerability Description

ScriptHelperApi in the AVG ScriptHelper ActiveX control in ScriptHelper.exe in AVG Secure Search toolbar before 18.1.7.598 and AVG Safeguard before 18.1.7.644 does not implement domain-based access control for method calls, which allows remote attackers to trigger the downloading and execution of arbitrary programs via a crafted web site.

CVSS Score

9.3

HIGH

AV:N/AC:M/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
AvgSafeguard<= 18.1.7
AvgSecure Search Toolbar<= 18.1.7

Related Weaknesses (CWE)

References

FAQ

What is CVE-2014-2956?

CVE-2014-2956 is a vulnerability with a CVSS score of 9.3 (HIGH). ScriptHelperApi in the AVG ScriptHelper ActiveX control in ScriptHelper.exe in AVG Secure Search toolbar before 18.1.7.598 and AVG Safeguard before 18.1.7.644 does not implement domain-based access co...

How severe is CVE-2014-2956?

CVE-2014-2956 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2014-2956?

Check the references section above for vendor advisories and patch information. Affected products include: Avg Safeguard, Avg Secure Search Toolbar.