PT-2020-6377 · Prosoft · Prosoft Configurator

Published

2020-02-11

·

Updated

2020-03-25

·

CVE-2020-7474

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ProSoft Configurator versions 1.002 and prior
Description A vulnerability exists in ProSoft Configurator, related to an uncontrolled search path element, which could cause the execution of untrusted code when using double click to open a project file, potentially triggering the execution of a malicious DLL. This issue affects the PMEPXM0100 (H) module.
Recommendations For ProSoft Configurator versions 1.002 and prior, consider avoiding the use of double click to open project files until a patch is available. As a temporary workaround, restrict the execution of untrusted code by limiting the search path elements to trusted locations.

Fix

Uncontrolled Search Path Element

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-04336
CVE-2020-7474

Affected Products

Prosoft Configurator