CVE-2018-5204

CRITICAL

ML Report <2.18.628.5980 - RCE

Title source: llm
STIX 2.1

Description

ML Report version Between 2.00.000.0000 and 2.18.628.5980 contains a vulnerability that could allow remote attacker to download and execute remote arbitrary file by setting the arguments to the activex method. this can be leveraged for code execution.

References (1)

Core 1
Core References

Scores

CVSS v3 9.8
EPSS 0.0200
EPSS Percentile 83.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-434
Status published
Products (1)
infraware-global/ml_report 2.00.000.0000 - 2.18.628.5980
Published Dec 28, 2018
Tracked Since Feb 18, 2026