CVE-2008-7168
EXPLOITED IN THE WILDUUSee UUUpgrade <3.0.2.12 - Code Injection
Title source: llmExploitation Summary
CVE-2008-7168 has been observed exploited in the wild (reported by VulnCheck KEV, InTheWild.io). EIP tracks 1 public exploit from researchers including Symantec.
AI-analyzed exploit summary This exploit leverages a vulnerability in UUSee 2008 to download and save malicious files to arbitrary locations on the affected system. The PoC uses an ActiveX control to trigger the Update method with attacker-controlled arguments.
Description
Insecure method vulnerability in the UUSee UUUpgrade ActiveX control (UUUpgrade.ocx 3.0.2.12) allows remote attackers to force the download and overwrite of arbitrary files via crafted arguments to the Update method, as exploited in the wild in June 2009.
Exploits (1)
This exploit leverages a vulnerability in UUSee 2008 to download and save malicious files to arbitrary locations on the affected system. The PoC uses an ActiveX control to trigger the Update method with attacker-controlled arguments.