PT-2022-23358 · Scooter · Beyond Compare

Published

2022-07-23

·

Updated

2022-08-01

·

CVE-2022-36415

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Scooter Beyond Compare versions 1.8a through 4.4.2
Description A DLL hijacking issue exists in the uninstaller when installed via the EXE installer. The uninstaller attempts to load DLLs from the Windows Temp folder. If a standard user places malicious DLLs in the C:WindowsTemp folder and the uninstaller is run as SYSTEM, the DLLs will execute with elevated privileges.
Recommendations For versions 1.8a through 4.4.2, update to version 4.4.3 or later to resolve the issue.

Fix

Uncontrolled Search Path Element

Weakness Enumeration

Related Identifiers

CVE-2022-36415

Affected Products

Beyond Compare