EXPOSURES › CVE-2014-8361
CVE-2014-8361
HIGH ⌖ ON CISA KEV · EXPLOITEDRealtek SDK allows remote code execution via improper input validation.
The Realtek SDK contains an improper input validation vulnerability in the miniigd SOAP service, allowing remote attackers to execute malicious code via a crafted NewInternalClient request. This vulnerability is actively exploited and poses a significant risk to systems using the SDK.
Shame score — The vulnerability is actively exploited and allows remote code execution, indicating a significant security risk.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Realtek SDK contains an improper input validation vulnerability in the miniigd SOAP service that allows remote attackers to execute malicious code via a crafted NewInternalClient request.