peter bassill · operator
$ cve CVE-2008-5002 JSON

CVE-2008-5002 EXPLOIT

9.3
HIGH · CVSS 2.0 · EPSS 40.7% (pctl 99)

Patch early

A public exploit exists.

Description

Insecure method vulnerability in the ChilkatCrypt2.ChilkatCrypt2.1 ActiveX control (ChilkatCrypt2.dll 4.3.2.1) in Chilkat Crypt ActiveX Component allows remote attackers to create and overwrite arbitrary files via the WriteFile method. NOTE: this could be leveraged for code execution by creating executable files in Startup folders or by accessing files using hcp:// URLs. NOTE: some of these details are obtained from third party information.

Scoring

CVSS9.3 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS40.66% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-20
On CISA KEVno
Public exploityes
Published2008-11-10
Last modified2026-06-16

Affected (1)

VendorProduct
chilkat softwarechilkat crypt activex control

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD