PT-2020-2064 · Schneider Electric · Vijeo Designer Basic+1
Published
2020-04-14
·
Updated
2022-01-31
·
CVE-2020-7490
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Vijeo Designer Basic versions V1.1 HotFix 15 and prior
Vijeo Designer versions V6.9 SP9 and prior
Description
A vulnerability exists in the software related to untrusted search paths, which could allow an attacker to execute arbitrary code on the system when a malicious DLL library is loaded. This issue is associated with errors in checking the path of loaded dynamic libraries.
Recommendations
For Vijeo Designer Basic versions V1.1 HotFix 15 and prior, update to a version later than V1.1 HotFix 15 to resolve the issue.
For Vijeo Designer versions V6.9 SP9 and prior, update to a version later than V6.9 SP9 to resolve the issue.
As a temporary workaround, consider restricting the loading of external DLL libraries to minimize the risk of exploitation.
Fix
Untrusted Search Path
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vijeo Designer
Vijeo Designer Basic