CVE-2019-12811

CRITICAL

MyBuilder < 6.2.2019.814 - OS Command Injection via ShellOpen Method

Title source: llm
STIX 2.1

Description

ActiveX Control in MyBuilder before 6.2.2019.814 allow an attacker to execute arbitrary command via the ShellOpen method. This can be leveraged for code execution

References (1)

Core 1
Core References

Scores

CVSS v3 9.8
EPSS 0.0216
EPSS Percentile 79.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Products (1)
activesoft/mybuilder < 6.2.2019.814
Published Oct 07, 2019
Tracked Since Feb 18, 2026