Uncontrolled search path element vulnerability in Plesk Installer affects version 3.27.0.0. A local attacker could execute arbitrary code by injecting DLL files into the same folder where the application is installed, resulting in DLL hijacking in edputil.dll, samlib.dll, urlmon.dll, sspicli.dll, propsys.dll and profapi.dll files.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published: 2023-11-27T14:12:40.130Z

Updated: 2024-08-02T07:44:53.183Z

Reserved: 2023-09-13T11:30:25.604Z

Link: CVE-2023-4931

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2023-11-27T14:15:07.930

Modified: 2023-12-01T19:06:42.203

Link: CVE-2023-4931

cve-icon Redhat

No data.