Vulnerabilities > CVE-2008-1886 - Cryptographic Issues vulnerability in Cdnetworks Download Client

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
cdnetworks
CWE-310
exploit available

Summary

The NeffyLauncher 1.0.5 ActiveX control (NeffyLauncher.dll) in CDNetworks Nefficient Download uses weak cryptography for a KeyCode that blocks unauthorized use of the control, which allows remote attackers to bypass this protection mechanism by calculating the required KeyCode. NOTE: this can be used by arbitrary web sites to host exploit code that targets this control.

Vulnerable Configurations

Part Description Count
Application
Cdnetworks
1

Common Weakness Enumeration (CWE)

Common Attack Pattern Enumeration and Classification (CAPEC)

  • Signature Spoofing by Key Recreation
    An attacker obtains an authoritative or reputable signer's private signature key by exploiting a cryptographic weakness in the signature algorithm or pseudorandom number generation and then uses this key to forge signatures from the original signer to mislead a victim into performing actions that benefit the attacker.

Exploit-Db

descriptionCDNetworks Nefficient Download (NeffyLauncher.dll) Code Execution Vuln. CVE-2008-1885,CVE-2008-1886. Remote exploit for windows platform
fileexploits/windows/remote/5397.txt
idEDB-ID:5397
last seen2016-01-31
modified2008-04-07
platformwindows
port
published2008-04-07
reporterSimon Ryeo
sourcehttps://www.exploit-db.com/download/5397/
titleCDNetworks Nefficient Download NeffyLauncher.dll Code Execution Vuln
typeremote