Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-5457

Опубликовано: 06 фев. 2018
Источник: nvd
CVSS3: 7
CVSS2: 6.9
EPSS Низкий

Описание

A uncontrolled search path element issue was discovered in Vyaire Medical CareFusion Upgrade Utility used with Windows XP systems, Versions 2.0.2.2 and prior versions. A successful exploit of this vulnerability requires the local user to install a crafted DLL on the target machine. The application loads the DLL and gives the attacker access at the same privilege level as the application.

Ссылки

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:a:vyaire:carefusion_upgrade_utility:*:*:*:*:*:*:*:*
Версия до 2.0.2.2 (включая)
cpe:2.3:o:microsoft:windows_xp:-:*:*:*:*:*:*:*

EPSS

Процентиль: 23%
0.00073
Низкий

7 High

CVSS3

6.9 Medium

CVSS2

Дефекты

CWE-427
CWE-427

Связанные уязвимости

CVSS3: 7
github
больше 3 лет назад

A uncontrolled search path element issue was discovered in Vyaire Medical CareFusion Upgrade Utility used with Windows XP systems, Versions 2.0.2.2 and prior versions. A successful exploit of this vulnerability requires the local user to install a crafted DLL on the target machine. The application loads the DLL and gives the attacker access at the same privilege level as the application.

EPSS

Процентиль: 23%
0.00073
Низкий

7 High

CVSS3

6.9 Medium

CVSS2

Дефекты

CWE-427
CWE-427