CyberRota Analysis
AI-GeneratedproCertum SmartSign is vulnerable due to its failure to validate the schema of Certificate Practice Statement (CPS) URIs, allowing attackers to craft malicious certificates that can execute arbitrary local files or open URLs when a victim interacts with a signed document. This vulnerability poses a significant risk as it can lead to unauthorized code execution on the victim's system. Organizations using affected versions of proCertum SmartSign should prioritize updating to version 9.4.3.90 to mitigate this risk.
Original NVD Description
proCertum SmartSign opens Certificate Practice Statement (CPS) URI without schema validation. An attacker can prepare arbitrary certificate with CPS URI pointing to a local executable file or any URL, sign a document with it, and send it to the victim. When the victim opens the document in the application, the specified file will be executed (or webpage will be opened). This issue was fixed in version 9.4.3.90.