Vulnerabilities > CVE-2007-2853 - Remote Command Execution vulnerability in H+H Software Virtual CD VC9API.DLL ActiveX

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
h-h
critical
exploit available

Summary

The VCDAPILibApi ActiveX control in vc9api.DLL 9.0.0.57 in Virtual CD 9.0.0.2 allows remote attackers to execute arbitrary commands via a command line in the first argument to the VCDLaunchAndWait function.

Vulnerable Configurations

Part Description Count
Application
H\+H
2

Exploit-Db

descriptionVirtual CD 9.0.0.2 (vc9api.DLL) Remote Shell Commands Execution Exploit. CVE-2007-2853. Remote exploit for windows platform
fileexploits/windows/remote/3967.html
idEDB-ID:3967
last seen2016-01-31
modified2007-05-21
platformwindows
port
published2007-05-21
reporterrgod
sourcehttps://www.exploit-db.com/download/3967/
titleVirtual CD 9.0.0.2 vc9api.DLL Remote Shell Commands Execution Exploit
typeremote