An arbitrary file download and execution vulnerability was found in the HShell.dll of handysoft Co., Ltd groupware ActiveX module. This issue is due to missing support for integrity check of download URL or downloaded file hash.
References
Link | Resource |
---|---|
https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=36239 | Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: krcert
Published: 2021-09-09T12:54:23
Updated: 2021-09-09T12:54:23
Reserved: 2021-02-03T00:00:00
Link: CVE-2021-26608
JSON object: View
NVD Information
Status : Analyzed
Published: 2021-09-09T13:15:08.543
Modified: 2022-08-02T15:52:41.767
Link: CVE-2021-26608
JSON object: View
Redhat Information
No data.