PT-2024-38155 · Mp3Tag · Mp3Tag
Daniel Soriano
+1
·
Published
2024-07-29
·
Updated
2024-11-20
·
CVE-2024-7193
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Mp3tag versions up to 3.26d
Description
A vulnerability has been found in the library tak deco lib.dll of the component DLL Handler, leading to an uncontrolled search path. The manipulation can be launched on the local host. It is possible to exploit this issue, and the exploit has been disclosed to the public. The vendor was contacted and responded professionally, releasing a fixed version of the affected product.
Recommendations
For Mp3tag versions up to 3.26d, upgrade to version 3.26e to address this issue.
As a temporary workaround, consider restricting access to the
tak deco lib.dll library until the upgrade is applied.Exploit
Fix
Uncontrolled Search Path Element
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mp3Tag