CVE-2019-12809: YES24 Viewer Activex

High severity, CVSS 8.8. EPSS: 1% chance of exploitation in the next 30 days.

Yes24ViewerX ActiveX Control 1.0.327.50126 and earlier versions contains a vulnerability that could allow remote attackers to download and execute arbitrary files by setting the arguments to the ActiveX method. This can be leveraged for code execution.

Affected products

  • YES24 Viewer Activex: up to and including 1.0.327.50126

Published 2019-08-15. Last modified 2026-06-17.