CVE-2008-4342
Summary
| CVE | CVE-2008-4342 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-09-30 17:22:09 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | NuMedia Soft NMS DVD Burning SDK Activex NMSDVDX.DVDEngineX.1 ActiveX control (NMSDVDX.dll) 1.013C and earlier, as used in CDBurnerXP 4.2.1.976, BurnAware 2.1.3, Blaze Media Pro 8.02 Special Edition, and possibly other products, allows remote attackers to overwrite and create arbitrary files via calls to the EnableLog and LogMessage methods. NOTE: this issue might only be exploitable in limited environments or non-default browser settings. NOTE: some of these details are obtained from third party information. NOTE: this can be leveraged for remote code execution by accessing files using hcp:// URLs. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:M/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Burnaware Technologies | Burnaware | 2.1.3 | unknown | free | All |
| Application | Burnaware Technologies | Burnaware | 2.1.3 | unknown | home | All |
| Application | Burnaware Technologies | Burnaware | 2.1.3 | unknown | professional | All |
| Application | Impressum | Cdburnerxp | 4.2.1.976 | All | All | All |
| Application | Numedia Soft | Numedia Dvd Burning Sdk | 1.008 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.shinnai.net/xplits/TXT_TrWE9AJA8nQpuFsnxBcq | af854a3a-2127-422b-91ae-364da2661108 | www.shinnai.net | Exploit, URL Repurposed |
| Blaze Media Pro NMSDVDX ActiveX Control Insecure Methods - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| BurnAware NMSDVDX ActiveX Control Insecure Methods - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| CDBurnerXP Pro NMSDVDX ActiveX Control Insecure Methods - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| NuMedia Soft NMS DVD Burning SDK Activex (NMSDVDX.dll) Exploit | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | |
| NMS DVD Burning SDK ActiveX Control Insecure Methods - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| NMS DVD Burning SDK 'NMSDVDX.dll' ActiveX Control Arbitrary File Overwrite Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit |
| NuMedia Soft NMS DVD Burning SDK Activex (NMSDVDX.dll) remote exploit | af854a3a-2127-422b-91ae-364da2661108 | retrogod.altervista.org | Exploit |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.