CVE-2019-6453

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
18/02/2019
Last modified:
24/08/2020

Description

mIRC before 7.55 allows remote command execution by using argument injection through custom URI protocol handlers. The attacker can specify an irc:// URI that loads an arbitrary .ini file from a UNC share pathname. Exploitation depends on browser-specific URI handling (Chrome is not exploitable).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mirc:mirc:*:*:*:*:*:*:*:* 7.55 (excluding)