A uncontrolled search path element issue was discovered in Vyaire Medical CareFusion Upgrade Utility used with Windows XP systems, Versions 2.0.2.2 and prior versions. A successful exploit of this vulnerability requires the local user to install a crafted DLL on the target machine. The application loads the DLL and gives the attacker access at the same privilege level as the application.
2018-02-06T21:29:00.473
2024-11-21T04:08:50.283
Modified
CVSSv3.0: 7.0 (HIGH)
AV:L/AC:M/Au:N/C:C/I:C/A:C
3.4
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | vyaire | carefusion_upgrade_utility | ≤ 2.0.2.2 | Yes |
Operating System | microsoft | windows_xp | - | No |