Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-47636

Опубликовано: 10 авг. 2023
Источник: nvd
CVSS3: 7.8
EPSS Низкий

Описание

A DLL hijacking vulnerability has been discovered in OutSystems Service Studio 11 11.53.30 build 61739. When a user open a .oml file (OutSystems Modeling Language), the application will load the following DLLs from the same directory av_libGLESv2.dll, libcef.DLL, user32.dll, and d3d10warp.dll. Using a crafted DLL, it is possible to execute arbitrary code in the context of the current logged in user.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:outsystems:service_studio:11.53.30:*:*:*:*:*:*:*

EPSS

Процентиль: 29%
0.00106
Низкий

7.8 High

CVSS3

Дефекты

CWE-427

Связанные уязвимости

CVSS3: 7.8
github
больше 2 лет назад

A DLL hijacking vulnerability has been discovered in OutSystems Service Studio 11 11.53.30 build 61739. When a user open a .oml file (OutSystems Modeling Language), the application will load the following DLLs from the same directory av_libGLESv2.dll, libcef.DLL, user32.dll, and d3d10warp.dll. Using a crafted DLL, it is possible to execute arbitrary code in the context of the current logged in user.

EPSS

Процентиль: 29%
0.00106
Низкий

7.8 High

CVSS3

Дефекты

CWE-427