Ashampoo 3D CAD Professional 3 ActiveX control Insecure Method
Advisory ID: | HTB23019 |
Product: | Ashampoo 3D CAD Professional 3 |
Vendor: | Ashampoo GmbH & Co |
Vulnerable Versions: | 3.0.1 and probably prior |
Tested Version: | 3.0.1 |
Advisory Publication: | June 7, 2011 [without technical details] |
Vendor Notification: | June 7, 2011 |
Public Disclosure: | June 28, 2011 |
Latest Update: | June 28, 2011 |
Vulnerability Type: | Exposed Unsafe ActiveX Method [CWE-618] |
Risk Level: | Critical |
CVSSv2 Base Score: | 9.3 (AV:N/AC:M/Au:N/C:C/I:C/A:C) |
Solution Status: | Fixed by Vendor |
Discovered and Provided: | High-Tech Bridge Security Research Lab |
Advisory Details: | |
High-Tech Bridge SA Security Research Lab has discovered a vulnerability in Ashampoo 3D CAD Professional 3 ActiveX control which could be exploited to compromise vulnerable system. | |
Solution: | |
Upgrade to 3.0.2 or later version. http://ashampoo.downloadcluster.com/ashampoo/0560/ashampoo_3d_cad_professional_3_3.0.2_sm.exe | |
References: | |
[1] High-Tech Bridge Advisory HTB23019 - https://www.immuniweb.com/advisory/HTB23019 - Ashampoo 3D CAD Professional 3 ActiveX control Insecure Method [2] Ashampoo 3D CAD Professional 3 ActiveX control - ashampoo.com – An ActiveX control for Ashampoo 3D CAD Professional. [3] Common Weakness Enumeration (CWE) - http://cwe.mitre.org - targeted to developers and security practitioners, CWE is a formal list of software weakness types. | |
HTB23015: Easewe FTP ActiveX Control Multiple Insecure Methods
HTB23016: Kofax e-Transactions Sender Sendbox ActiveX Control Insecure Method
Please feel free to send us any additional information related to this Advisory, such as vulnerable versions, additional exploitation details and conditions, patches and other relevant details.