« Volver al listado

CVE-2008-7053

Estado: ModificadaAlta (9.3)—

LogMeIn Remote Access Utility ActiveX control (RACtrl.dll) allows remote attackers to cause a denial of service (crash) by setting the fgcolor and bgcolor properties to certain long values that trigger memory corruption.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2008-7053",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 9.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": true,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2009-08-24T19:30:00.250",
  "references": [
    {
      "url": "http://packetstorm.foofus.com/0808-exploits/logmein-activex.txt",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/30923",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/44843",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-7053",
      "tags": [
        "US Government Resource"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.exploit-db.com/exploits/6326",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://packetstorm.foofus.com/0808-exploits/logmein-activex.txt",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/30923",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/44843",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-7053",
      "tags": [
        "US Government Resource"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.exploit-db.com/exploits/6326",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-399"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "LogMeIn Remote Access Utility ActiveX control (RACtrl.dll) allows remote attackers to cause a denial of service (crash) by setting the fgcolor and bgcolor properties to certain long values that trigger memory corruption."
    },
    {
      "lang": "es",
      "value": "Control ActiveX LogMeIn Remote Access Utility (RACtrl.dll) permite a atacantes remotos provocar una denegación de servicio (caída) al configurar las propiedades de fgcolor y bgcolor a determinados valores largos que provocan una corrupción de memoria."
    }
  ],
  "lastModified": "2026-06-16T23:03:30.160",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:logmein:ractrl.dll:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A4A11944-3639-4AE1-B080-BD1859E65C72"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "vendorComments": [
    {
      "comment": "LogMeIn is aware of the CVE-2008-7053 issue and has resolved it on 9/3/2008. The fix is included in LogMeIn ActiveX Plugin since version 392-G2.”",
      "lastModified": "2014-06-18T13:31:40.190",
      "organization": "LogMeIn"
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}