VulnerabilityModified
CVE-2014-0619
Untrusted search path vulnerability in Hamster Free ZIP Archiver 2.0.1.7 allows local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the current working directory.
MEDIUM 6.9EPSS 0.64%
Does this matter?
Lower severity and a low EPSS score (0.64%). Track it; it rarely justifies an emergency change on its own.
Description
Untrusted search path vulnerability in Hamster Free ZIP Archiver 2.0.1.7 allows local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the current working directory.
- CVSS 2.0
- 6.9 MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 0.64% probability · 49th percentile
- CISA KEV
- Not listed
- Affected
- hamstersoft/hamster free zip archiver
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/128739/Hamster-Free-ZIP-Archiver-2.0.1.7-DLL-Hijacking.htmlExploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/97658
- http://packetstormsecurity.com/files/128739/Hamster-Free-ZIP-Archiver-2.0.1.7-DLL-Hijacking.htmlExploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/97658
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.