PoC Index

CVE-2008-4388

HIGH 9.3EPSS 37.7%

The LaunchObj ActiveX control before 5.2.2.865 in launcher.dll in Symantec AppStream Client 5.2.x before 5.2.2 SP3 MP1 does not properly validate downloaded files, which allows remote attackers to execute arbitrary code via the installAppMgr method and unspecified other methods.

CVSS v2.0
9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS
37.72% chance of exploitation in the next 30 days, 98th percentile
Published
2009-01-20
Updated
2024-09-16

Metasploit modules (1)

ExploitDB entries (1)

References

Related