CVE-2019-9141 HIGH

CVE-2019-9141: Zoneplayer ActiveX Remote Code Execution vulnerability

Vendor Imgtech Co,Ltd
Product ZInsVX.dll ActiveX Control
Weakness CWE-20 · Input validation
Published August 2, 2019
Last update September 16, 2024

CVSS base score

8.8/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality High
Integrity High

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

ZInsVX.dll ActiveX Control 2018.02 and earlier in Zoneplayer contains a vulnerability that could allow remote attackers to execute arbitrary files by setting the arguments to the ActiveX method. This can be leveraged for remote code execution.

Key dates

02Disclosure timeline

August 2, 2019 CVE published
September 16, 2024 Record updated