PT-2022-12477 · Acer · Acer Care Center

Federico Lagrasta

+1

·

Published

2022-01-26

·

Updated

2022-02-02

·

CVE-2021-45975

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Acer Care Center versions 4.x before 4.00.3038
Description The issue is due to incorrect handling of directory search paths at run time in the loading mechanism of Windows DLLs, allowing a local attacker to perform a DLL hijacking attack. An attacker could exploit this by placing a malicious DLL file on the targeted system, which will execute when the vulnerable application launches, potentially allowing the attacker to execute arbitrary code on the targeted system with local administrator privileges.
Recommendations For Acer Care Center versions 4.x before 4.00.3038, update to version 4.00.3038 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable ListCheck.exe application until a patch is applied. Avoid placing untrusted DLL files on the system to minimize the risk of exploitation.

Exploit

Fix

Untrusted Search Path

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-45975

Affected Products

Acer Care Center