CVE-2008-4342
NuMedia Soft NMS DVD Burning SDK Activex NMSDVDX.DVDEngineX.1 ActiveX control (NMSDVDX.dll) 1.013C and earlier, as used in CDBurnerXP 4.2.1.976, BurnAware 2.1.3, Blaze Media Pro 8.02 Special Edition, and possibly other products, allows remote attackers to overwrite and create arbitrary files via calls to the EnableLog and LogMessage methods. NOTE: this issue might only be exploitable in limited environments or non-default browser settings. NOTE: some of these details are obtained from third party information. NOTE: this can be leveraged for remote code execution by accessing files using hcp:// URLs.
CVSS
- Version: 2.0
- Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C
- Base score: 9.3
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 17%
- Percentile among all scored CVEs: 97
- Score date: 10/6/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
💥 Public exploits
Exploit code or detection templates are publicly available. This is not the same as confirmed active exploitation (KEV), but it raises the risk: patch with priority.
- Published on Exploit-DB · NuMedia Soft Nms DVD Burning SDK - ActiveX 'NMSDVDX.dll' Command Execution (9/19/2008)
Affected technologies (3)
CWEs
- CWE-20
References
- http://retrogod.altervista.org/9sg_numedia_xpl.html
- http://secunia.com/advisories/31936
- http://secunia.com/advisories/31949
- http://secunia.com/advisories/31950
- http://secunia.com/advisories/32455
- http://www.securityfocus.com/archive/1/497831/100/0/threaded
- http://www.securityfocus.com/bid/31374
- http://www.shinnai.net/xplits/TXT_TrWE9AJA8nQpuFsnxBcq
- http://www.vupen.com/english/advisories/2008/2663
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45330
- https://www.exploit-db.com/exploits/6491
- http://retrogod.altervista.org/9sg_numedia_xpl.html
- http://secunia.com/advisories/31936
- http://secunia.com/advisories/31949
- http://secunia.com/advisories/31950
- http://secunia.com/advisories/32455
- http://www.securityfocus.com/archive/1/497831/100/0/threaded
- http://www.securityfocus.com/bid/31374
- http://www.shinnai.net/xplits/TXT_TrWE9AJA8nQpuFsnxBcq
- http://www.vupen.com/english/advisories/2008/2663
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45330
- https://www.exploit-db.com/exploits/6491
Raw JSON (NVD)
Show
{
"id": "CVE-2008-4342",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 9.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2008-09-30T17:22:09.507",
"references": [
{
"url": "http://retrogod.altervista.org/9sg_numedia_xpl.html",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/31936",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/31949",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/31950",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/32455",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/497831/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/31374",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.shinnai.net/xplits/TXT_TrWE9AJA8nQpuFsnxBcq",
"tags": [
"Exploit",
"URL Repurposed"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2008/2663",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/45330",
"source": "cve@mitre.org"
},
{
"url": "https://www.exploit-db.com/exploits/6491",
"source": "cve@mitre.org"
},
{
"url": "http://retrogod.altervista.org/9sg_numedia_xpl.html",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/31936",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/31949",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/31950",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/32455",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/497831/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/31374",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.shinnai.net/xplits/TXT_TrWE9AJA8nQpuFsnxBcq",
"tags": [
"Exploit",
"URL Repurposed"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2008/2663",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/45330",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.exploit-db.com/exploits/6491",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "NuMedia Soft NMS DVD Burning SDK Activex NMSDVDX.DVDEngineX.1 ActiveX control (NMSDVDX.dll) 1.013C and earlier, as used in CDBurnerXP 4.2.1.976, BurnAware 2.1.3, Blaze Media Pro 8.02 Special Edition, and possibly other products, allows remote attackers to overwrite and create arbitrary files via calls to the EnableLog and LogMessage methods. NOTE: this issue might only be exploitable in limited environments or non-default browser settings. NOTE: some of these details are obtained from third party information. NOTE: this can be leveraged for remote code execution by accessing files using hcp:// URLs."
},
{
"lang": "es",
"value": "El control ActiveX de NMSDVDX.DVDEngineX.1 (biblioteca NMSDVDX.dll) de NuMedia Soft NMS DVD Burning SDK Activex versión 1.013C y anteriores, tal como es usado en CDBurnerXP versión 4.2.1.976, BurnAware versión 2.1.3, Blaze Media Pro versión 8.02 Edición Especial, y posiblemente otros productos, permite a los atacantes remotos sobrescribir y crear archivos arbitrarios por medio de llamadas a los métodos EnableLog y LogMessage. NOTA: este problema solo podría ser explotable en entornos limitados o configuraciones de navegador no predeterminadas. NOTA: algunos de estos detalles son obtenidos de información de terceros. NOTA: esto puede ser aprovechado para la ejecución de código remota mediante el acceso a archivos usando las URL hcp://."
}
],
"lastModified": "2026-06-16T22:57:38.290",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:burnaware_technologies:burnaware:2.1.3:unknown:free:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "68B389E7-BC30-4955-826F-C391031ED019"
},
{
"criteria": "cpe:2.3:a:burnaware_technologies:burnaware:2.1.3:unknown:home:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FFCB0E22-3CA2-4785-882E-C63F17B7F731"
},
{
"criteria": "cpe:2.3:a:burnaware_technologies:burnaware:2.1.3:unknown:professional:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2545356E-7888-42FA-A5A5-A7C63C4B953D"
},
{
"criteria": "cpe:2.3:a:impressum:cdburnerxp:4.2.1.976:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0CF01099-9B7D-478C-BC6F-283930174F91"
},
{
"criteria": "cpe:2.3:a:numedia_soft:numedia_dvd_burning_sdk:1.008:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FF824977-059F-45C0-8B36-C058FDBB6376"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}