Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-1435

Опубликовано: 14 мар. 2018
Источник: nvd
CVSS3: 7.8
CVSS2: 6.8
EPSS Низкий

Описание

IBM Notes 8.5 and 9.0 is vulnerable to a DLL hijacking attack. A remote attacker could trick a user to double click a malicious executable in an attacker-controlled directory, which could result in code execution. IBM X-Force ID: 139563.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:ibm:notes:8.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:notes:8.5.0.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:notes:8.5.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:notes:8.5.1.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:notes:8.5.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:notes:8.5.2.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:notes:8.5.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:notes:8.5.3.6:*:*:*:*:*:*:*
cpe:2.3:a:ibm:notes:9.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:notes:9.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:notes:9.0.1.9:*:*:*:*:*:*:*

EPSS

Процентиль: 76%
0.00991
Низкий

7.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-426

Связанные уязвимости

CVSS3: 7.8
github
больше 3 лет назад

IBM Notes 8.5 and 9.0 is vulnerable to a DLL hijacking attack. A remote attacker could trick a user to double click a malicious executable in an attacker-controlled directory, which could result in code execution. IBM X-Force ID: 139563.

EPSS

Процентиль: 76%
0.00991
Низкий

7.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-426