Skip to content
COOEY

EXPOSURES › CVE-2014-8361

CVE-2014-8361

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2023-09-18 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2014-8361 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatched

Realtek SDK allows remote code execution via improper input validation.

The Realtek SDK contains an improper input validation vulnerability in the miniigd SOAP service, allowing remote attackers to execute malicious code via a crafted NewInternalClient request. This vulnerability is actively exploited and poses a significant risk to systems using the SDK.

Shame score — The vulnerability is actively exploited and allows remote code execution, indicating a significant security risk.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Realtek SDK contains an improper input validation vulnerability in the miniigd SOAP service that allows remote attackers to execute malicious code via a crafted NewInternalClient request.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.