CVE-2008-4926 describes multiple insecure method vulnerabilities within the MW6 Technologies PDF417 ActiveX control (MW6PDF417Lib.PDF417, MW6PDF417.dll) version 3.0.0.1. These flaws allow remote, authenticated attackers to overwrite arbitrary files on a system by providing a full pathname to the SaveAsBMP and SaveAsWMF methods. With a CVSS score of 9.0, this vulnerability is considered critical, indicating a high potential for impact. An attacker can exploit this remotely with low complexity, leading to complete compromise of confidentiality, integrity, and availability of the affected system. While there is no evidence of active exploitation in the wild (not in KEV or Hot List), an exploit module for Metasploit is not available, but an ExploitDB entry (EDB-6873) confirms the existence of public exploit code. Community discussion and media coverage for this CVE are minimal, which is typical for a large percentage of CVEs.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.0.0.1CPE matchmatch criteria | cpe:2.3:a:mw6_technologies:pdf417_activex:3.0.0.1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:S/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.