Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hhvv-gx6c-p7jj

Опубликовано: 30 нояб. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

An uncontrolled search path element vulnerability has been found on 4D and 4D server Windows executables applications, affecting version 19 R8 100218. This vulnerability consists in a DLL hijacking by replacing x64 shfolder.dll in the installation path, causing an arbitrary code execution.

An uncontrolled search path element vulnerability has been found on 4D and 4D server Windows executables applications, affecting version 19 R8 100218. This vulnerability consists in a DLL hijacking by replacing x64 shfolder.dll in the installation path, causing an arbitrary code execution.

EPSS

Процентиль: 38%
0.00164
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-427

Связанные уязвимости

CVSS3: 6.5
nvd
около 2 лет назад

An uncontrolled search path element vulnerability has been found on 4D and 4D server Windows executables applications, affecting version 19 R8 100218. This vulnerability consists in a DLL hijacking by replacing x64 shfolder.dll in the installation path, causing an arbitrary code execution.

EPSS

Процентиль: 38%
0.00164
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-427