Vulnerability Description
The vulnerabilty was discovered in ActiveX module related to NeoRS remote support program. This issue allows an remote attacker to download and execute remote file. It is because of improper parameter validation of StartNeoRS function in ActiveX.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Douzone | Neors | <= rs10 |
| Microsoft | Windows | - |
Related Weaknesses (CWE)
References
- https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=36367Third Party Advisory
- https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=36367Third Party Advisory
FAQ
What is CVE-2020-7880?
CVE-2020-7880 is a vulnerability with a CVSS score of 7.5 (HIGH). The vulnerabilty was discovered in ActiveX module related to NeoRS remote support program. This issue allows an remote attacker to download and execute remote file. It is because of improper parameter...
How severe is CVE-2020-7880?
CVE-2020-7880 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-7880?
Check the references section above for vendor advisories and patch information. Affected products include: Douzone Neors, Microsoft Windows.