CVE-2008-5002

Chilkat Software Chilkat Crypt Active... - Improper Input Validation

Title source: rule

Description

Insecure method vulnerability in the ChilkatCrypt2.ChilkatCrypt2.1 ActiveX control (ChilkatCrypt2.dll 4.3.2.1) in Chilkat Crypt ActiveX Component allows remote attackers to create and overwrite arbitrary files via the WriteFile method. NOTE: this could be leveraged for code execution by creating executable files in Startup folders or by accessing files using hcp:// URLs. NOTE: some of these details are obtained from third party information.

Exploits (3)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/16518
exploitdb WORKING POC VERIFIED
by shinnai · htmlremotewindows
https://www.exploit-db.com/exploits/6963
metasploit WORKING POC EXCELLENT
by shinnai, jduck · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/browser/chilkat_crypt_writefile.rb

Scores

EPSS 0.6842
EPSS Percentile 98.6%

Details

CWE
CWE-20
Status published
Products (1)
chilkat_software/chilkat_crypt_activex_control 2.1
Published Nov 10, 2008
Tracked Since Feb 18, 2026