A DLL hijacking vulnerability exists in Schneider Electric Software Update (SESU), all versions prior to V2.2.0, which could allow an attacker to execute arbitrary code on the targeted system when placing a specific DLL file.
The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/105951 | vdb entry third party advisory |
https://www.schneider-electric.com/en/download/document/SEVD-2018-298-01/ | vendor advisory |
https://ics-cert.us-cert.gov/advisories/ICSA-18-305-02 | third party advisory us government resource |