CVE-2024-7326
IObit DualSafe Password Manager BPL RTL120.BPL uncontrolled search path
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability classified as critical has been found in IObit DualSafe Password Manager 1.4.0.3. This affects an unknown part in the library RTL120.BPL of the component BPL Handler. The manipulation leads to uncontrolled search path. It is possible to launch the attack on the local host. The identifier VDB-273249 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Es wurde eine Schwachstelle in IObit DualSafe Password Manager 1.4.0.3 entdeckt. Sie wurde als kritisch eingestuft. Betroffen hiervon ist ein unbekannter Ablauf in der Bibliothek RTL120.BPL der Komponente BPL Handler. Durch das Beeinflussen mit unbekannten Daten kann eine uncontrolled search path-Schwachstelle ausgenutzt werden. Der Angriff muss lokal erfolgen.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2024-07-31 CVE Reserved
- 2024-07-31 CVE Published
- 2024-08-06 CVE Updated
- 2024-08-16 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-427: Uncontrolled Search Path Element
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://lab52.io/blog/dll-side-loading-through-iobit-against-colombia | Related | |
https://vuldb.com/?id.273249 | Vdb Entry | |
https://vuldb.com/?submit.378150 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
IObit Search vendor "IObit" | DualSafe Password Manager Search vendor "IObit" for product "DualSafe Password Manager" | 1.4.0.3 Search vendor "IObit" for product "DualSafe Password Manager" and version "1.4.0.3" | en |
Affected
|