PT-2023-27998 · Ezviz · Ezviz Studio
Published
2023-12-04
·
Updated
2023-12-07
·
CVE-2023-41613
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
EzViz Studio version 2.2.0
Description
The issue concerns DLL hijacking, which is a type of vulnerability that occurs when an application loads a malicious DLL file instead of the legitimate one. This can lead to arbitrary code execution and potentially allow attackers to gain control over the system.
Recommendations
For EzViz Studio version 2.2.0, as a temporary workaround, consider restricting the loading of external DLL files until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Uncontrolled Search Path Element
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ezviz Studio