CVE-2007-1684

critical

Description

The Run function in SolidWorks sldimdownload ActiveX control in sldimdownload.dll before 16.0.0.6 allows remote attackers to execute arbitrary commands via the (1) installerpath and (2) applicationarguments arguments.

References

https://exchange.xforce.ibmcloud.com/vulnerabilities/33428

http://www.vupen.com/english/advisories/2007/1216

http://www.securitytracker.com/id?1017855

http://www.securityfocus.com/bid/23290

http://www.kb.cert.org/vuls/id/556801

http://secunia.com/advisories/24762

http://osvdb.org/34320

Details

Source: Mitre, NVD

Published: 2007-04-06

Updated: 2024-11-21

Risk Information

CVSS v2

Base Score: 9.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical