Impact
HMO) contains a DLL hijacking flaw that permits an attacker to supply the application’s load process. This weakness, identified as CWE‑427, undermines the integrity of the add‑on, potentially allowing arbitrary code to run with the same rights as the Outlook add‑on. If exploited, an attacker could alter Outlook behavior or enumerate information on the host.
Affected Systems
The issue affects the HCL Traveler for Microsoft Outlook product from HCL Software. No specific version numbers are listed, implying that any deployment of this add‑on is potentially vulnerable until a vendor patch is issued. The.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, amplified by the EPSS score of less than 1 %, which suggests that exploitation is not currently widespread. The vulnerability is not listed in CISA’s KEV catalog. While the DLL hijacking typically necessitates the ability to place a malicious library in a directory searched by the application, implying that local file‑write access is likely needed. Because this is inferred from the nature of the flaw, the attack vector is considered local unless additional information emerges.
OpenCVE Enrichment