The GIGABYTE Dldrv2 ActiveX control 1.4.206.11 allows remote attackers to (1) download arbitrary programs onto a client system, and execute these programs, via vectors involving the dl method; and (2) download arbitrary programs onto a client system via vectors involving the SetDLInfo method in conjunction with the Bdl method.
References
Link | Resource |
---|---|
http://secunia.com/secunia_research/2010-85/ | Vendor Advisory |
http://secunia.com/advisories/40161 | Vendor Advisory |
Configurations
Information
Published : 2010-08-02 13:40
Updated : 2010-08-02 21:00
NVD link : CVE-2010-1517
Mitre link : CVE-2010-1517
JSON object : View
CWE
CWE-20
Improper Input Validation
Products Affected
gigabyte
- dldrv2_activex_control