Lucene search

K
cveJpcertCVE-2024-28099
HistoryApr 15, 2024 - 11:15 a.m.

CVE-2024-28099

2024-04-1511:15:08
CWE-427
jpcert
web.nvd.nist.gov
31
vt studio
ver.8.32
dll
vulnerability
dynamic link libraries
insecure loading

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

7.3

Confidence

Low

EPSS

0

Percentile

9.0%

VT STUDIO Ver.8.32 and earlier contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries. As a result, arbitrary code may be executed with the privileges of the running application.

Affected configurations

Vulners
Node
keyence_corporationvt_studioMatch8.32
VendorProductVersionCPE
keyence_corporationvt_studio8.32cpe:2.3:a:keyence_corporation:vt_studio:8.32:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "KEYENCE CORPORATION",
    "product": "VT STUDIO",
    "versions": [
      {
        "version": "Ver.8.32 and earlier",
        "status": "affected"
      }
    ]
  }
]

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

7.3

Confidence

Low

EPSS

0

Percentile

9.0%

Related for CVE-2024-28099