PT-2012-5960 · Activestate · Activetcl

Publicado

2012-10-11

·

Atualizado

2013-03-02

·

CVE-2012-5378

CVSS v2.0

6.0

Média

VetorAV:L/AC:H/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions ActiveTcl version 8.5.12
Description The issue concerns an untrusted search path vulnerability in the installation functionality. This vulnerability allows local users to gain privileges via a Trojan horse DLL in the C:TDbin directory. The vulnerability is demonstrated by a Trojan horse wlbsctrl.dll file used by the "IKE and AuthIP IPsec Keying Modules" system service in various Windows versions.
Recommendations For ActiveTcl version 8.5.12, consider removing the C:TDbin directory from the PATH system environment variable to prevent exploitation. As a temporary workaround, restrict access to the C:TDbin directory to minimize the risk of a Trojan horse DLL being loaded.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2012-5378

Produtos afetados

Activetcl