Vulnerability Description
Insufficient Verification of input Data leading to arbitrary file download and execute was discovered in Nexacro platform. This vulnerability is caused by an automatic update function that does not verify input data except version information. Remote attackers can use this incomplete validation logic to download and execute arbitrary malicious file.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tobesoft | Nexacro | >= 17.0.0, < 17.1.3.700 |
| Microsoft | Windows | - |
Related Weaknesses (CWE)
References
- https://www.krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=66661Third Party Advisory
- https://www.krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=66661Third Party Advisory
FAQ
What is CVE-2021-26625?
CVE-2021-26625 is a vulnerability with a CVSS score of 8.8 (HIGH). Insufficient Verification of input Data leading to arbitrary file download and execute was discovered in Nexacro platform. This vulnerability is caused by an automatic update function that does not ve...
How severe is CVE-2021-26625?
CVE-2021-26625 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-26625?
Check the references section above for vendor advisories and patch information. Affected products include: Tobesoft Nexacro, Microsoft Windows.