A certain ActiveX control in the EDraw Office Viewer Component (edrawofficeviewer.ocx) 4.0.5.20, and other versions before 5.0, allows remote attackers to delete arbitrary files via the DeleteLocalFile method.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Office_viewer_component | Edraw | * | 5.0 (including) |
Office_viewer_component | Edraw | 4.0.5.20 (including) | 4.0.5.20 (including) |