PT-2024-38155 · Mp3Tag · Mp3Tag

Daniel Soriano

+1

·

Published

2024-07-29

·

Updated

2024-11-20

·

CVE-2024-7193

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Mp3tag versions up to 3.26d
Description A vulnerability has been found in the library tak deco lib.dll of the component DLL Handler, leading to an uncontrolled search path. The manipulation can be launched on the local host. It is possible to exploit this issue, and the exploit has been disclosed to the public. The vendor was contacted and responded professionally, releasing a fixed version of the affected product.
Recommendations For Mp3tag versions up to 3.26d, upgrade to version 3.26e to address this issue. As a temporary workaround, consider restricting access to the tak deco lib.dll library until the upgrade is applied.

Exploit

Fix

Uncontrolled Search Path Element

Weakness Enumeration

Related Identifiers

CVE-2024-7193

Affected Products

Mp3Tag