o Handysoft, Inc. released security update to address file download and execution vulnerability in Groupware ActiveX Control.
|File Donwload and Execution
o hslogin2.dll ActiveX Control in Groupware contains a vulnerability that could allow remote files to be downloaded and executed by setting the arguments to the activex method. (CVE-2020-7810)
o A remote attacker could induce a user to access a crafted web page, causing damage such as malicious code infection.
□ Affected Product
||18.104.22.168 and prior
7.3.4 and prior
o Update software over hslogin2.dll ActiveX Control 22.214.171.12402 / 126.96.36.199 version or higher.
o Thanks to Eunsol Lee for reporting this vulnerability.
□ 작성 : 침해사고분석단 취약점분석팀