A DLL hijacking vulnerability exists in Schneider Electric's SoMove Software and associated DTM software components in all versions prior to 2.6.2 which could allow an attacker to execute arbitrary code.
The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.
Link | Tags |
---|---|
https://ics-cert.us-cert.gov/advisories/ICSA-18-065-02 | third party advisory us government resource |
https://www.schneider-electric.com/en/download/document/SEVD-2018-060-01/ | vendor advisory |
http://www.securityfocus.com/bid/103338 | third party advisory vdb entry |