Vulnerabilities > CVE-2007-3493

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
microsoft
nctsoft-products
exploit available

Summary

A certain ActiveX control in NCTWavChunksEditor2.dll 2.6.1.148 in NCTAudioStudio (NCTAudioStudio2) 2.7, as used by Sienzo DMM and probably other products, allows remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the CreateFile method, a different product than CVE-2007-3400.

Exploit-Db

descriptionNCTAudioStudio2 ActiveX DLL 2.6.1.148 CreateFile() Insecure Method. CVE-2007-3493. Remote exploit for windows platform
fileexploits/windows/remote/4109.html
idEDB-ID:4109
last seen2016-01-31
modified2007-06-26
platformwindows
port
published2007-06-26
reportershinnai
sourcehttps://www.exploit-db.com/download/4109/
titleNCTAudioStudio2 - ActiveX DLL 2.6.1.148 CreateFile Insecure Method
typeremote