CVE-2019-19166

Current Description

Tobesoft XPlatform v9.1, 9.2.0, 9.2.1 and 9.2.2 have a vulnerability that can load unauthorized DLL files. It allows attacker to cause remote code execution.

Basic Data

PublishedMay 06, 2020
Last ModifiedMay 07, 2020
Assignercve@mitre.org
Data TypeCVE
Data FormatMITRE
Data Version4.0
Problem TypeNVD-CWE-noinfo
CVE Data Version4.0

Base Metric V2

CVSS 2 - Version2.0
CVSS 2 - Vector StringAV:L/AC:M/Au:N/C:P/I:P/A:P
CVSS 2 - Access VectorLOCAL
CVSS 2 - Access ComplexityMEDIUM
CVSS 2 - AuthenticationNONE
CVSS 2 - Confidentiality ImpactPARTIAL
CVSS 2 - Availability ImpactPARTIAL
CVSS 2 - Base Score4.4
SeverityMEDIUM
Exploitability Score3.4
Impact Score6.4
Obtain All Privilegefalse
Obtain User Privilegefalse
Obtain Other Privilegefalse

Base Metric V3

No data provided.

Configurations

  • AND
    • OR - Configuration 1
      Cpe VersionPartVendorProductVersionUpdateEditionLanguageSW EditionTarget SWTarget HWOtherVersion Start IncludingVersion End IncludingVersion Start ExcludingVersion End Excluding
      2.3ApplicationTobesoftXplatform9.1*******
      2.3ApplicationTobesoftXplatform9.2.0*******
      2.3ApplicationTobesoftXplatform9.2.1*******
      2.3ApplicationTobesoftXplatform9.2.2*******
    • OR Running on/with:
      Cpe VersionPartVendorProductVersionUpdateEditionLanguageSW EditionTarget SWTarget HWOtherVersion Start IncludingVersion End IncludingVersion Start ExcludingVersion End Excluding
      2.3OSMicrosoftWindows-*******

Vulnerable Software List

VendorProductVersions
Tobesoft Xplatform 9.1, 9.2.0, 9.2.1, 9.2.2

References

NameSourceURLTags
http://support.tobesoft.co.kr/Support/index.htmlhttp://support.tobesoft.co.kr/Support/index.htmlMISCVendor Advisory
https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=35357https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=35357MISCThird Party Advisory