PT-2022-4816 · Unknown · Ma Smart Installer
Published
2022-07-26
·
Updated
2022-08-02
·
CVE-2022-2313
CVSS v3.1
8.2
High
| Vector | AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
MA Smart Installer for Windows versions prior to 5.7.7
Description
The issue is related to a DLL hijacking vulnerability, which allows local users to execute arbitrary code and obtain higher privileges via careful placement of a malicious DLL into the folder from where the Smart installer is being executed. This vulnerability is associated with the possibility of substituting a dynamic library, potentially enabling an attacker to execute arbitrary code or elevate their privileges.
Recommendations
For versions prior to 5.7.7, update to version 5.7.7 or later to resolve the issue. As a temporary workaround, consider restricting access to the folder from where the Smart installer is being executed to minimize the risk of exploitation.
Fix
Uncontrolled Search Path Element
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ma Smart Installer