PT-2022-12477 · Acer · Acer Care Center
Federico Lagrasta
+1
·
Published
2022-01-26
·
Updated
2022-02-02
·
CVE-2021-45975
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Acer Care Center versions 4.x before 4.00.3038
Description
The issue is due to incorrect handling of directory search paths at run time in the loading mechanism of Windows DLLs, allowing a local attacker to perform a DLL hijacking attack. An attacker could exploit this by placing a malicious DLL file on the targeted system, which will execute when the vulnerable application launches, potentially allowing the attacker to execute arbitrary code on the targeted system with local administrator privileges.
Recommendations
For Acer Care Center versions 4.x before 4.00.3038, update to version 4.00.3038 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable ListCheck.exe application until a patch is applied. Avoid placing untrusted DLL files on the system to minimize the risk of exploitation.
Exploit
Fix
Untrusted Search Path
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Acer Care Center