PT-2017-19313 · Schneider Electric · Pro-Face Gp Pro Ex

Published

2017-09-25

·

Updated

2019-10-03

·

CVE-2017-9961

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Schneider Electric's Pro-Face GP Pro EX version 4.07.000
Description A security issue exists that allows an attacker to execute arbitrary code. This can be achieved by placing a specific DLL/OCX file, which forces the process to load an arbitrary DLL and execute code in the context of the process. The attacker needs access to the computer to install malicious code.
Recommendations For version 4.07.000, consider restricting access to the computer and avoid using potentially vulnerable DLL/OCX files until a fix is available. As a temporary workaround, restrict the loading of arbitrary DLLs to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2017-9961

Affected Products

Pro-Face Gp Pro Ex