CVE-2008-5002 EXPLOIT
9.3
HIGH · CVSS 2.0 · EPSS 40.7% (pctl 99)
Patch early
A public exploit exists.
Description
Insecure method vulnerability in the ChilkatCrypt2.ChilkatCrypt2.1 ActiveX control (ChilkatCrypt2.dll 4.3.2.1) in Chilkat Crypt ActiveX Component allows remote attackers to create and overwrite arbitrary files via the WriteFile method. NOTE: this could be leveraged for code execution by creating executable files in Startup folders or by accessing files using hcp:// URLs. NOTE: some of these details are obtained from third party information.
Scoring
| CVSS | 9.3 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
| EPSS | 40.66% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-20 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2008-11-10 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| chilkat software | chilkat crypt activex control |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Chilkat Crypt - ActiveX WriteFile Unsafe Method (Metasploit) | 2010-09-20 |
| exploit-db | Chilkat Crypt - ActiveX Arbitrary File Creation/Execution | 2008-11-03 |
References
- http://secunia.com/advisories/32513
- http://securityreason.com/securityalert/4571
- http://www.securityfocus.com/bid/32073
- http://www.vupen.com/english/advisories/2008/2998
- https://exchange.xforce.ibmcloud.com/vulnerabilities/46315
- https://www.exploit-db.com/exploits/6963
- http://secunia.com/advisories/32513
- http://securityreason.com/securityalert/4571
- http://www.securityfocus.com/bid/32073
- http://www.vupen.com/english/advisories/2008/2998
- https://exchange.xforce.ibmcloud.com/vulnerabilities/46315
- https://www.exploit-db.com/exploits/6963
→ the Explorer · watch your stack · NVD