Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c4qv-5j2j-52m7

Опубликовано: 29 окт. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 8.4

Описание

DLL hijacking vulnerability in Evope Collector 1.1.6.9.0 and related components load the wtsapi32.dll library from an uncontrolled search path (C:\ProgramData\Evope). This allows local unprivileged attackers to execute arbitrary code or escalate privileges to SYSTEM by placing a crafted DLL in that location. The vulnerable component is Evope.Service.exe, which runs with SYSTEM privileges and automatically loads the DLL on startup or reboot.

DLL hijacking vulnerability in Evope Collector 1.1.6.9.0 and related components load the wtsapi32.dll library from an uncontrolled search path (C:\ProgramData\Evope). This allows local unprivileged attackers to execute arbitrary code or escalate privileges to SYSTEM by placing a crafted DLL in that location. The vulnerable component is Evope.Service.exe, which runs with SYSTEM privileges and automatically loads the DLL on startup or reboot.

EPSS

Процентиль: 5%
0.00021
Низкий

8.4 High

CVSS3

Дефекты

CWE-427

Связанные уязвимости

CVSS3: 8.4
nvd
3 месяца назад

DLL hijacking vulnerability in Evope Collector 1.1.6.9.0 and related components load the wtsapi32.dll library from an uncontrolled search path (C:\ProgramData\Evope). This allows local unprivileged attackers to execute arbitrary code or escalate privileges to SYSTEM by placing a crafted DLL in that location. The vulnerable component is Evope.Service.exe, which runs with SYSTEM privileges and automatically loads the DLL on startup or reboot.

EPSS

Процентиль: 5%
0.00021
Низкий

8.4 High

CVSS3

Дефекты

CWE-427