Описание
A DLL hijacking vulnerability was identified in the Qognify VMS Client Viewer version 7.1 or higher, which allows local users to execute arbitrary code and obtain higher privileges via careful placement of a malicious DLL, if some specific pre-conditions are met.
Ссылки
- ExploitMailing ListThird Party Advisory
- ExploitThird Party Advisory
- ExploitMailing ListThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 7.1 (включая)
cpe:2.3:a:hexagon:qognify_vms_client_viewer:*:*:*:*:*:*:*:*
EPSS
Процентиль: 17%
0.00055
Низкий
6.7 Medium
CVSS3
Дефекты
CWE-427
CWE-427
Связанные уязвимости
CVSS3: 6.7
github
почти 2 года назад
A DLL hijacking vulnerability was identified in the Qognify VMS Client Viewer version 7.1 or higher, which allows local users to execute arbitrary code and obtain higher privileges via careful placement of a malicious DLL, if some specific pre-conditions are met.
EPSS
Процентиль: 17%
0.00055
Низкий
6.7 Medium
CVSS3
Дефекты
CWE-427
CWE-427