A DLL hijacking vulnerability was identified in the Qognify VMS Client Viewer version 7.1 or higher, which allows local users to execute arbitrary code and obtain higher privileges via careful placement of a malicious DLL, if some specific pre-conditions are met.
Solution:
The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.
Link | Tags |
---|---|
https://r.sec-consult.com/qognify | third party advisory exploit |
http://seclists.org/fulldisclosure/2024/Mar/10 | mailing list third party advisory exploit |