PT-2022-4816 · Unknown · Ma Smart Installer

Published

2022-07-26

·

Updated

2022-08-02

·

CVE-2022-2313

CVSS v3.1

8.2

High

VectorAV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MA Smart Installer for Windows versions prior to 5.7.7
Description The issue is related to a DLL hijacking vulnerability, which allows local users to execute arbitrary code and obtain higher privileges via careful placement of a malicious DLL into the folder from where the Smart installer is being executed. This vulnerability is associated with the possibility of substituting a dynamic library, potentially enabling an attacker to execute arbitrary code or elevate their privileges.
Recommendations For versions prior to 5.7.7, update to version 5.7.7 or later to resolve the issue. As a temporary workaround, consider restricting access to the folder from where the Smart installer is being executed to minimize the risk of exploitation.

Fix

Uncontrolled Search Path Element

Weakness Enumeration

Related Identifiers

BDU:2022-05824
CVE-2022-2313

Affected Products

Ma Smart Installer