A vulnerability has been identified in ModelSim (All versions < V2024.3), Questa (All versions < V2024.3). vish2.exe in affected applications allows a specific DLL file to be loaded from the current working directory. This could allow an authenticated local attacker to inject arbitrary code and escalate privileges in installations where administrators or processes with elevated privileges launch vish2.exe from a user-writable directory.
Metrics
Affected Vendors & Products
References
History
Tue, 08 Oct 2024 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Siemens
Siemens modelsim Siemens questa |
|
CPEs | cpe:2.3:a:siemens:modelsim:*:*:*:*:*:*:*:* cpe:2.3:a:siemens:questa:*:*:*:*:*:*:*:* |
|
Vendors & Products |
Siemens
Siemens modelsim Siemens questa |
|
Metrics |
ssvc
|
Tue, 08 Oct 2024 08:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability has been identified in ModelSim (All versions < V2024.3), Questa (All versions < V2024.3). vish2.exe in affected applications allows a specific DLL file to be loaded from the current working directory. This could allow an authenticated local attacker to inject arbitrary code and escalate privileges in installations where administrators or processes with elevated privileges launch vish2.exe from a user-writable directory. | |
Weaknesses | CWE-427 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: siemens
Published: 2024-10-08T08:40:46.551Z
Updated: 2024-10-08T17:12:45.619Z
Reserved: 2024-09-20T15:14:29.689Z
Link: CVE-2024-47194
Vulnrichment
Updated: 2024-10-08T17:12:33.370Z
NVD
Status : Analyzed
Published: 2024-10-08T09:15:17.047
Modified: 2024-10-16T18:15:04.043
Link: CVE-2024-47194
Redhat
No data.