OpenOrange Business Framework version 1.15.5 installs to a directory with overly permissive access control, allowing all authenticated users to write to the installation path. In combination with the application's behavior of loading DLLs from this location, this allows for DLL hijacking and may result in arbitrary code execution and privilege escalation.
History

Fri, 29 Aug 2025 19:45:00 +0000

Type Values Removed Values Added
Description OpenOrange Business Framework 1.15.5 provides unprivileged users with write access to the installation directory. OpenOrange Business Framework version 1.15.5 installs to a directory with overly permissive access control, allowing all authenticated users to write to the installation path. In combination with the application's behavior of loading DLLs from this location, this allows for DLL hijacking and may result in arbitrary code execution and privilege escalation.

Thu, 07 Aug 2025 21:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 07 Aug 2025 17:00:00 +0000


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-08-29T19:35:04.557Z

Reserved: 2024-07-28T00:00:00.000Z

Link: CVE-2024-42048

cve-icon Vulnrichment

Updated: 2025-08-07T20:35:14.821Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-08-07T17:15:27.060

Modified: 2025-08-29T20:15:34.227

Link: CVE-2024-42048

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.