CVE-2019-12809

HIGH

Yes24 Viewer Activex - Download Without Integrity Check

Title source: rule
STIX 2.1

Description

Yes24ViewerX ActiveX Control 1.0.327.50126 and earlier versions contains a vulnerability that could allow remote attackers to download and execute arbitrary files by setting the arguments to the ActiveX method. This can be leveraged for code execution.

Scores

CVSS v3 8.8
EPSS 0.0038
EPSS Percentile 59.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-494
Status published
Products (1)
yes24/viewer_activex < 1.0.327.50126
Published Aug 15, 2019
Tracked Since Feb 18, 2026