Naver Cloud Explorer Beta allows the attacker to execute arbitrary code as System privilege via malicious DLL injection.
📦
cloud_explorer
Vendor: naver
Actively Exploited
0
CISA KEV List
PoC / Exploits
0
Code Available
Total RCEs
2
Remote Access
Total CVEs
6
Total Indexed
Avg. EPSS
0.74%
Exploit Prob.
Security Vulnerability Index
Page 1 / 1
7.8
CVSS
CVE-2022-24077
RCE
Severity: HIGH
9.8
CVSS
Naver Cloud Explorer before 2.2.2.11 allows the attacker can move a local file in any path on the filesystem as a system privilege through its named pipe.
Severity: CRITICAL
9.1
CVSS
Naver Cloud Explorer before 2.2.2.11 allows the system to download an arbitrary file from the attacker's server and execute it during the upgrade.
Severity: CRITICAL
7.5
CVSS
CVE-2019-13156
RCE
NDrive(1.2.2).sys in Naver Cloud Explorer has a stack-based buffer overflow, which allows attackers to cause a denial of service when reading data from IOCTL handle.
Severity: HIGH