PT-2018-17722 · Swisscom · Myswisscomassistant

Published

2018-03-27

·

Updated

2019-10-03

·

CVE-2018-6765

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MySwisscomAssistant version 2.17.1.1065
Description The issue allows an unauthenticated, remote attacker to execute arbitrary code on the targeted system due to the way .dll files are loaded. This is possible because an attacker can load a .dll of their choosing, which could execute arbitrary code without the user's knowledge. The specific flaw exists within the handling of several DLLs, including dwmapi.dll, IPHLPAPI.DLL, WindowsCodecs.dll, RpcRtRemote.dll, CRYPTSP.dll, rasadhlp.dll, DNSAPI.dll, ntmarta.dll, netbios.dll, olepro32.dll, security.dll, winhttp.dll, and WINSTA.dll, loaded by the MySwisscomAssistant Setup.exe process.
Recommendations For MySwisscomAssistant version 2.17.1.1065, consider restricting the loading of external .dll files by the MySwisscomAssistant Setup.exe process as a temporary mitigation measure until a patch is available. Additionally, avoid using the affected MySwisscomAssistant Setup.exe process until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Uncontrolled Search Path Element

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-6765

Affected Products

Myswisscomassistant