Untrusted search path vulnerability in the installer of Content Transfer (for Windows) Ver.1.3 and prior allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.
Link | Tags |
---|---|
https://www.sony.jp/support/audiosoftware/contenttransfer/ | product vendor advisory |
https://jvn.jp/en/jp/JVN40620121/index.html | third party advisory |