4.3
CVSSv2

CVE-2008-1933

Published: 25/04/2008 Updated: 11/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Absolute path traversal vulnerability in a certain ActiveX control in Zune allows user-assisted remote malicious users to overwrite arbitrary files via the SaveToFile method. NOTE: the victim must explicitly allow the code to run.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft zune software

Exploits

Vulnerability class : Arbitrary file overwrite Discovery date : 21 April 2008 Remote : Yes Credits : J Bachmann & B Mariani from ilion Research Labs Vulnerable : Zune software: EncProfile2 Class An arbitrary file overwrite as been discovered in an ActiveX control installed with the Zune software package If a user visits the malicious page a ...