// For flags

CVE-2020-7360

Philips SmartControl DLL Hijacking

Severity Score

7.3
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

An Uncontrolled Search Path Element (CWE-427) vulnerability in SmartControl version 4.3.15 and versions released before April 15, 2020 may allow an authenticated user to escalate privileges by placing a specially crafted DLL file in the search path. This issue was fixed in version 1.0.7, which was released after April 15, 2020. (Note, the version numbering system changed significantly between version 4.3.15 and version 1.0.7.)

(CWE-427) Una vulnerabilidad de Elemento Ruta Búsqueda no Controlada en SmartControl versión 4.3.15 y versiones publicadas antes del 15 de abril de 2020, puede permitir a un usuario autenticado escalar privilegios al colocar un archivo DLL especialmente diseñado en la ruta de búsqueda. Este problema fue corregido en la versión 1.0.7, que fue publicado después del 15 de abril de 2020 (tome en cuenta que el sistema de numeración de versiones cambió significativamente entre la versión 4.3.15 y la versión 1.0.7)

*Credits: This issue was discovered and reported by Erik Wynter of Vonahi Security.
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Local
Attack Complexity
High
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
High
Integrity
High
Availability
Low
Attack Vector
Local
Attack Complexity
Medium
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2020-01-21 CVE Reserved
  • 2020-08-13 CVE Published
  • 2023-12-17 EPSS Updated
  • 2024-09-17 CVE Updated
  • 2024-09-17 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-427: Uncontrolled Search Path Element
CAPEC
References (1)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Philips
Search vendor "Philips"
Smartcontrol
Search vendor "Philips" for product "Smartcontrol"
<= 4.3.15
Search vendor "Philips" for product "Smartcontrol" and version " <= 4.3.15"
-
Affected