What the vulnerability does

01Description

NAVER Toolbar before 4.0.30.323 allows remote attackers to execute arbitrary code via a crafted upgrade.xml file. Special characters in filename parameter can be the cause of bypassing code signing check function.

Key dates

02Disclosure timeline

July 19, 2021 CVE published
August 3, 2024 Record updated