Description
Loading a DLL through an Uncontrolled Search Path Element in the Bosch Configuration Manager installer up to and including version 7.21.0078 potentially allows an attacker to execute arbitrary code on a victim's system. A prerequisite is that the victim is tricked into placing a malicious DLL in the same directory where the installer is started from.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-27935 | Loading a DLL through an Uncontrolled Search Path Element in the Bosch Configuration Manager installer up to and including version 7.21.0078 potentially allows an attacker to execute arbitrary code on a victim's system. A prerequisite is that the victim is tricked into placing a malicious DLL in the same directory where the installer is started from. |
References
History
No history.
Status: PUBLISHED
Assigner: bosch
Published:
Updated: 2024-09-16T23:56:16.560Z
Reserved: 2020-01-10T00:00:00.000Z
Link: CVE-2020-6788
No data.
Status : Modified
Published: 2021-03-25T16:15:13.743
Modified: 2024-11-21T05:36:11.203
Link: CVE-2020-6788
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD