VulnerabilityAnalyzed
CVE-2023-49114
A DLL hijacking vulnerability was identified in the Qognify VMS Client Viewer version 7.1 or higher, which allows local users to execute arbitrary code and obtain higher privileges via careful placement of a malicious DLL, if some specific…
MEDIUM 6.7EPSS 0.36%
Does this matter?
Lower severity and a low EPSS score (0.36%). Track it; it rarely justifies an emergency change on its own.
Description
A DLL hijacking vulnerability was identified in the Qognify VMS Client Viewer version 7.1 or higher, which allows local users to execute arbitrary code and obtain higher privileges via careful placement of a malicious DLL, if some specific pre-conditions are met.
- CVSS 3.1
- 6.7 MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 0.36% probability · 29th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-427
- Affected
- hexagon/qognify vms client viewer
- Source
- 551230f0-3615-47bd-b7cc-93e92e730bbf
References
- http://seclists.org/fulldisclosure/2024/Mar/10Exploit, Mailing List, Third Party Advisory
- https://r.sec-consult.com/qognifyExploit, Third Party Advisory
- http://seclists.org/fulldisclosure/2024/Mar/10Exploit, Mailing List, Third Party Advisory
- https://r.sec-consult.com/qognifyExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.