Bosch · Bosch Ip Helper · CVE-2020-6771
Name of the Vulnerable Software and Affected Versions:
Bosch IP Helper versions prior to 1.00.0008
Description:
The issue allows an attacker to execute arbitrary code on a victim's system by loading a DLL through an uncontrolled search path element. This can happen if the victim is tricked into placing a malicious DLL in the same application directory as the portable IP Helper application.
Recommendations:
For versions prior to 1.00.0008, update to a version that contains a fix for this issue to prevent arbitrary code execution. As a temporary workaround, consider restricting access to the application directory to minimize the risk of exploitation.