Impact
The vulnerability arises from the way DYMO ID resolves the location of its plugin modules relative to the current working directory. By delivering a specially crafted job file alongside a malicious module or DLL, an attacker can trick the application into treating the job folder as its working directory. When the victim opens the file, the application loads the malicious DLL and executes it with the same privileges that the user process runs under, giving the attacker the ability to run arbitrary code on the system.
Affected Systems
This weakness has been documented for DYMO ID version 1.5.1.71 and is fixed in version 1.6.0. No other affected product versions are listed in the CNA data. The product is sold by Newell Brands.
Risk and Exploitability
The CVSS score of 7 indicates a moderate severity, and the lack of a published EPSS score means there is no publicly available evidence of exploitation, though the flaw is not listed in the CISA KEV catalog. Attackers would need local access to place the malicious job file and rely on a user opening the file, which makes the vulnerability a local privilege escalation that can lead to full code execution on the victim’s machine.
OpenCVE Enrichment