CVE-2018-5202

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
21/12/2018
Last modified:
03/10/2019

Description

SKCertService 2.5.5 and earlier contains a vulnerability that could allow remote attacker to execute arbitrary code. This vulnerability exists due to the way .dll files are loaded by SKCertService. It allows an attacker to load a .dll of the attacker's choosing that could execute arbitrary code without the user's knowledge.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:signkorea:skcertservice:*:*:*:*:*:*:*:* 2.5.5 (including)