← back
CVE-2020-7880

douzone NeoRS remote support program ActiveX vulnerability

CVSS 7.5 HIGHEPSS 1.6%CWE-20
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 7.5EPSS 1.6%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
30 Nov 2021Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The vulnerabilty was discovered in ActiveX module related to NeoRS remote support program. This issue allows an remote attacker to download and execute remote file. It is because of improper parameter validation of StartNeoRS function in ActiveX.
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products
douzone · NeoRS

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →