PT-2020-6377 · Prosoft · Prosoft Configurator
Published
2020-02-11
·
Updated
2020-03-25
·
CVE-2020-7474
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ProSoft Configurator versions 1.002 and prior
Description
A vulnerability exists in ProSoft Configurator, related to an uncontrolled search path element, which could cause the execution of untrusted code when using double click to open a project file, potentially triggering the execution of a malicious DLL. This issue affects the PMEPXM0100 (H) module.
Recommendations
For ProSoft Configurator versions 1.002 and prior, consider avoiding the use of double click to open project files until a patch is available. As a temporary workaround, restrict the execution of untrusted code by limiting the search path elements to trusted locations.
Fix
Uncontrolled Search Path Element
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Prosoft Configurator