PT-2023-15446 · Outsystems · Outsystems Service Studio

Carlo Di Dato

·

Published

2023-08-10

·

Updated

2023-08-17

·

CVE-2022-47636

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OutSystems Service Studio version 11.53.30 build 61739
Description A DLL hijacking issue has been discovered. When a user opens a .oml file, the application loads DLLs from the same directory, including av libGLESv2.dll, libcef.DLL, user32.dll, and d3d10warp.dll. Using a crafted DLL, it is possible to execute arbitrary code in the context of the current logged-in user.
Recommendations For OutSystems Service Studio version 11.53.30 build 61739, consider disabling the loading of DLLs from the same directory as a temporary workaround until a patch is available. Restrict access to the vulnerable DLLs to minimize the risk of exploitation. Avoid using the affected .oml file handling functionality until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Uncontrolled Search Path Element

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-47636

Affected Products

Outsystems Service Studio