An uncontrolled search path element vulnerability has been found on 4D and 4D server Windows executables applications, affecting version 19 R8 100218. This vulnerability consists in a DLL hijacking by replacing x64 shfolder.dll in the installation path, causing an arbitrary code execution.
2023-11-30T14:15:11.880
2024-11-21T08:35:56.800
Modified
CVSSv3.1: 6.5 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | 4d | 4d | 19 | Yes |
Application | 4d | server | 19 | Yes |
Operating System | microsoft | windows | - | No |