Vulnerability Description
A buffer overflow issue was discovered in ZOOK solution(remote administration tool) through processing 'ConnectMe' command while parsing a crafted OUTERIP value because of missing boundary check. This vulnerability allows the attacker to execute remote arbitrary command.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mastersoft | Zook Agent | 2.0.6.1 |
| Mastersoft | Zook Viewer | 2.0.4.6 |
| Microsoft | Windows | - |
Related Weaknesses (CWE)
References
- https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=36216Third Party Advisory
- https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=36216Third Party Advisory
FAQ
What is CVE-2020-7877?
CVE-2020-7877 is a vulnerability with a CVSS score of 8.0 (HIGH). A buffer overflow issue was discovered in ZOOK solution(remote administration tool) through processing 'ConnectMe' command while parsing a crafted OUTERIP value because of missing boundary check. This...
How severe is CVE-2020-7877?
CVE-2020-7877 has been rated HIGH with a CVSS base score of 8.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-7877?
Check the references section above for vendor advisories and patch information. Affected products include: Mastersoft Zook Agent, Mastersoft Zook Viewer, Microsoft Windows.