CVE-2020-7880 HIGH

CVE-2020-7880: douzone NeoRS remote support program ActiveX vulnerability

Vendor Douzone
Product NeoRS
Weakness CWE-20 · Input validation
Published November 30, 2021
Last update August 4, 2024

CVSS base score

7.5/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction Required
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

The vulnerabilty was discovered in ActiveX module related to NeoRS remote support program. This issue allows an remote attacker to download and execute remote file. It is because of improper parameter validation of StartNeoRS function in ActiveX.

Key dates

02Disclosure timeline

November 30, 2021 CVE published
August 4, 2024 Record updated