PT-2024-5611 · Iobit · Iobit Dualsafe Password Manager

Daniel.Soriano

·

Published

2024-07-31

·

Updated

2024-08-15

·

CVE-2024-7326

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IObit DualSafe Password Manager version 1.4.0.3
Description The issue is related to an uncontrolled search path element in the BPL Handler component of the IObit DualSafe Password Manager. This could allow an attacker to execute arbitrary commands. The attack can be launched on the local host.
Recommendations For IObit DualSafe Password Manager version 1.4.0.3, consider restricting access to the BPL Handler component until a patch is available. As a temporary workaround, avoid using the RTL120.BPL library in the BPL Handler component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Uncontrolled Search Path Element

Weakness Enumeration

Related Identifiers

BDU:2024-06303
CVE-2024-7326

Affected Products

Iobit Dualsafe Password Manager