PT-2017-19313 · Schneider Electric · Pro-Face Gp Pro Ex

Publicado

2017-09-25

·

Atualizado

2019-10-03

·

CVE-2017-9961

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Schneider Electric's Pro-Face GP Pro EX version 4.07.000
Description A security issue exists that allows an attacker to execute arbitrary code. This can be achieved by placing a specific DLL/OCX file, which forces the process to load an arbitrary DLL and execute code in the context of the process. The attacker needs access to the computer to install malicious code.
Recommendations For version 4.07.000, consider restricting access to the computer and avoid using potentially vulnerable DLL/OCX files until a fix is available. As a temporary workaround, restrict the loading of arbitrary DLLs to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2017-9961

Produtos afetados

Pro-Face Gp Pro Ex