CVE-2008-7168 EXPLOIT
9.3
HIGH · CVSS 2.0 · EPSS 5.6% (pctl 93)
Patch early
A public exploit exists.
Description
Insecure method vulnerability in the UUSee UUUpgrade ActiveX control (UUUpgrade.ocx 3.0.2.12) allows remote attackers to force the download and overwrite of arbitrary files via crafted arguments to the Update method, as exploited in the wild in June 2009.
Scoring
| CVSS | 9.3 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
| EPSS | 5.65% — more likely to be exploited than 93% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2009-09-08 |
| Last modified | 2026-06-16 |
Affected (2)
| Vendor | Product |
|---|---|
| uusee | uusee |
| uusee | uuupgrade.ocx |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | UUSee 2008 - UUUpgrade ActiveX Control 'Update' Method Arbitrary File Download | 2008-06-26 |
References
- http://downloads.securityfocus.com/vulnerabilities/exploits/29963.html
- http://www.securityfocus.com/bid/29963
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43428
- http://downloads.securityfocus.com/vulnerabilities/exploits/29963.html
- http://www.securityfocus.com/bid/29963
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43428
→ the Explorer · watch your stack · NVD