PT-2020-2064 · Schneider Electric · Vijeo Designer Basic+1

Published

2020-04-14

·

Updated

2022-01-31

·

CVE-2020-7490

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Vijeo Designer Basic versions V1.1 HotFix 15 and prior Vijeo Designer versions V6.9 SP9 and prior
Description A vulnerability exists in the software related to untrusted search paths, which could allow an attacker to execute arbitrary code on the system when a malicious DLL library is loaded. This issue is associated with errors in checking the path of loaded dynamic libraries.
Recommendations For Vijeo Designer Basic versions V1.1 HotFix 15 and prior, update to a version later than V1.1 HotFix 15 to resolve the issue. For Vijeo Designer versions V6.9 SP9 and prior, update to a version later than V6.9 SP9 to resolve the issue. As a temporary workaround, consider restricting the loading of external DLL libraries to minimize the risk of exploitation.

Fix

Untrusted Search Path

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-01898
CVE-2020-7490

Affected Products

Vijeo Designer
Vijeo Designer Basic