peter bassill · operator
$ cve CVE-2008-7168 JSON

CVE-2008-7168 EXPLOIT

9.3
HIGH · CVSS 2.0 · EPSS 5.6% (pctl 93)

Patch early

A public exploit exists.

Description

Insecure method vulnerability in the UUSee UUUpgrade ActiveX control (UUUpgrade.ocx 3.0.2.12) allows remote attackers to force the download and overwrite of arbitrary files via crafted arguments to the Update method, as exploited in the wild in June 2009.

Scoring

CVSS9.3 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS5.65% — more likely to be exploited than 93% of all CVEs
On CISA KEVno
Public exploityes
Published2009-09-08
Last modified2026-06-16

Affected (2)

VendorProduct
uuseeuusee
uuseeuuupgrade.ocx

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD