An uncontrolled search path element vulnerability (DLL hijacking) has been discovered that could allow a locally authenticated adversary to escalate privileges to SYSTEM. Alternatively, they could host a trojanized version of the software and trick victims into downloading and installing their malicious version to gain initial access and code execution.
2024-01-10T17:15:08.493
2024-11-21T07:57:04.190
Modified
CVSSv3.1: 6.3 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ptc | kepware_kepserverex | ≤ 6.14.263.0 | Yes |
Application | ptc | thingworx_kepware_server | ≤ 6.14.263.0 | Yes |
Application | ptc | thingworx_industrial_connectivity | ≤ 8.5 | Yes |