peter bassill · operator
$ cve CVE-2009-0811 JSON

CVE-2009-0811 EXPLOIT

9.3
HIGH · CVSS 2.0 · EPSS 5.5% (pctl 93)

Patch early

A public exploit exists.

Description

Insecure method vulnerability in the SopCast SopCore ActiveX control in sopocx.ocx 3.0.3.501 allows remote attackers to execute arbitrary programs via an executable file name in the argument to the SetExternalPlayer method.

Scoring

CVSS9.3 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS5.54% — more likely to be exploited than 93% of all CVEs
WeaknessCWE-94
On CISA KEVno
Public exploityes
Published2009-03-04
Last modified2026-06-16

Affected (1)

VendorProduct
sopcastsopcore activex control

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD