CVE-2008-4342

N/A Unknown
Published: September 30, 2008 Modified: April 23, 2026
View on NVD

Description

NuMedia Soft NMS DVD Burning SDK Activex NMSDVDX.DVDEngineX.1 ActiveX control (NMSDVDX.dll) 1.013C and earlier, as used in CDBurnerXP 4.2.1.976, BurnAware 2.1.3, Blaze Media Pro 8.02 Special Edition, and possibly other products, allows remote attackers to overwrite and create arbitrary files via calls to the EnableLog and LogMessage methods. NOTE: this issue might only be exploitable in limited environments or non-default browser settings. NOTE: some of these details are obtained from third party information. NOTE: this can be leveraged for remote code execution by accessing files using hcp:// URLs.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://secunia.com/advisories/31936
Source: cve@mitre.org
Vendor Advisory
http://secunia.com/advisories/31949
Source: cve@mitre.org
Vendor Advisory
http://secunia.com/advisories/31950
Source: cve@mitre.org
Vendor Advisory
http://secunia.com/advisories/32455
Source: cve@mitre.org
Vendor Advisory
http://www.securityfocus.com/bid/31374
Source: cve@mitre.org
Exploit
http://www.shinnai.net/xplits/TXT_TrWE9AJA8nQpuFsnxBcq
Source: cve@mitre.org
Exploit URL Repurposed
http://www.vupen.com/english/advisories/2008/2663
Source: cve@mitre.org
Vendor Advisory
http://retrogod.altervista.org/9sg_numedia_xpl.html
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
http://secunia.com/advisories/31936
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/31949
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/31950
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/32455
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://www.securityfocus.com/archive/1/497831/100/0/threaded
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/31374
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
http://www.shinnai.net/xplits/TXT_TrWE9AJA8nQpuFsnxBcq
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit URL Repurposed
http://www.vupen.com/english/advisories/2008/2663
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/45330
Source: af854a3a-2127-422b-91ae-364da2661108
https://www.exploit-db.com/exploits/6491
Source: af854a3a-2127-422b-91ae-364da2661108

22 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
21.2%
96th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

impressum burnaware_technologies numedia_soft