An Uncontrolled Search Path Element issue was discovered in Moxa SoftNVR-IA Live Viewer, Version 3.30.3122 and prior versions. An uncontrolled search path element (DLL Hijacking) vulnerability has been identified. To exploit this vulnerability, an attacker could rename a malicious DLL to meet the criteria of the application, and the application would not verify that the DLL is correct. The attacker needs to have administrative access to the default install location in order to plant the insecure DLL. Once loaded by the application, the DLL could run malicious code at the privilege level of the application.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: icscert
Published: 2018-01-18T19:00:00
Updated: 2024-08-05T14:55:35.703Z
Reserved: 2017-01-03T00:00:00
Link: CVE-2017-5170
Vulnrichment
No data.
NVD
Status : Modified
Published: 2018-01-18T19:29:00.283
Modified: 2024-11-21T03:27:11.783
Link: CVE-2017-5170
Redhat
No data.