CVE-2023-49114 Vulnerability Details
/
/
/
CVE-2023-49114 Metadata Quick Info
CVE Published: 26/02/2024 |
CVE Updated: 14/08/2024 |
CVE Year: 2023
Source: SEC-VLab |
Vendor: Qognify |
Product: VMS Client Viewer
Status : PUBLISHED
CVE-2023-49114 Description
A DLL hijacking vulnerability was identified in the Qognify VMS Client Viewer version 7.1 or higher, which allows local users to execute arbitrary code and obtain higher privileges via careful placement of a malicious DLL, if some specific pre-conditions are met.
Metrics
CVSS Version: 3.1 |
Base Score: n/a
Vector: n/a
l➤ Exploitability Metrics:
Attack Vector (AV)*
Attack Complexity (AC)*
Privileges Required (PR)*
User Interaction (UI)*
Scope (S)*
l➤ Impact Metrics:
Confidentiality Impact (C)*
Integrity Impact (I)*
Availability Impact (A)*
Weakness Enumeration (CWE)
CWE-ID: CWE-427
CWE Name: CWE-427 Uncontrolled Search Path Element
Source: Qognify
Common Attack Pattern Enumeration and Classification (CAPEC)
CAPEC-ID: CAPEC-233
CAPEC Description: CAPEC-233 Privilege Escalation
Source: NVD (National Vulnerability Database).