CVE-2023-4931

U

ncontrolled search path element vulnerability in Plesk Installer affects version 3.27.0.0. A local attacker could execute arbitrary code by injecting DLL files into the same folder where the application is installed, resulting in DLL hijacking in edputil.dll, samlib.dll, urlmon.dll, sspicli.dll, propsys.dll and profapi.dll files.

Configurations

Configuration 1 (hide)

cpe:2.3:a:plesk:plesk:3.27.0.0:*:*:*:*:*:*:*

History

21 Nov 2024, 08:36

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.8
v2 : unknown
v3 : 6.3
References () https://support.plesk.com/hc/en-us/articles/17426121182103 - Vendor Advisory () https://support.plesk.com/hc/en-us/articles/17426121182103 - Vendor Advisory
References () https://www.incibe.es/en/incibe-cert/notices/aviso/uncontrolled-search-path-element-vulnerability-plesk - Third Party Advisory () https://www.incibe.es/en/incibe-cert/notices/aviso/uncontrolled-search-path-element-vulnerability-plesk - Third Party Advisory

Information

Published : 2023-11-27 14:15

Updated : 2024-11-21 08:36


NVD link : CVE-2023-4931

Mitre link : CVE-2023-4931

CVE.ORG link : CVE-2023-4931


JSON object : View

Products Affected
CWE
CWE-427

Uncontrolled Search Path Element