Description
The ActiveScan Installer ActiveX control in as2stubie.dll before 1.3.3.0 in PandaActiveScan Installer 2.0 in Panda ActiveScan downloads software in an as2guiie.cab archive located at an arbitrary URL, and does not verify the archive's digital signature before installation, which allows remote attackers to execute arbitrary code via a URL argument to an unspecified method.
Published: 2010-02-11
Score: 9.3 Critical
EPSS: 8.1% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2009-3707 The ActiveScan Installer ActiveX control in as2stubie.dll before 1.3.3.0 in PandaActiveScan Installer 2.0 in Panda ActiveScan downloads software in an as2guiie.cab archive located at an arbitrary URL, and does not verify the archive's digital signature before installation, which allows remote attackers to execute arbitrary code via a URL argument to an unspecified method.
History

No history.

Subscriptions

Panda Panda Activescan
cve-icon MITRE

Status: PUBLISHED

Assigner: certcc

Published:

Updated: 2024-08-07T06:38:30.251Z

Reserved: 2009-10-22T00:00:00.000Z

Link: CVE-2009-3735

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2010-02-11T17:30:00.610

Modified: 2025-04-11T00:51:21.963

Link: CVE-2009-3735

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses