Tobesoft NEXACRO14/17 ExCommonApiV13 Arbitrary Code Execution Vulnerability
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.8epss 1.6%
exploitation probability
1.6%top 26% of all CVEs
observed exploitation
nono source reports it
Nexacro14/17 ExtCommonApiV13 Library under 2019.9.6 version contain a vulnerability that could allow remote attacker to execute arbitrary code by setting the arguments to the vulnerable API. This can be leveraged for code execution by rebooting the victim’s PC
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products
Tobesoft · NEXACRO14/17 ExCommonApiV13