PT-2018-17722 · Swisscom · Myswisscomassistant
Published
2018-03-27
·
Updated
2019-10-03
·
CVE-2018-6765
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
MySwisscomAssistant version 2.17.1.1065
Description
The issue allows an unauthenticated, remote attacker to execute arbitrary code on the targeted system due to the way .dll files are loaded. This is possible because an attacker can load a .dll of their choosing, which could execute arbitrary code without the user's knowledge. The specific flaw exists within the handling of several DLLs, including
dwmapi.dll, IPHLPAPI.DLL, WindowsCodecs.dll, RpcRtRemote.dll, CRYPTSP.dll, rasadhlp.dll, DNSAPI.dll, ntmarta.dll, netbios.dll, olepro32.dll, security.dll, winhttp.dll, and WINSTA.dll, loaded by the MySwisscomAssistant Setup.exe process.Recommendations
For MySwisscomAssistant version 2.17.1.1065, consider restricting the loading of external .dll files by the
MySwisscomAssistant Setup.exe process as a temporary mitigation measure until a patch is available. Additionally, avoid using the affected MySwisscomAssistant Setup.exe process until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Uncontrolled Search Path Element
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Myswisscomassistant