ZeroHour

CVE-2018-5457

CVSS 3.0
7.0 high
EPSS
<1%p29
Published
()
Modified
Description

A uncontrolled search path element issue was discovered in Vyaire Medical CareFusion Upgrade Utility used with Windows XP systems, Versions 2.0.2.2 and prior versions. A successful exploit of this vulnerability requires the local user to install a crafted DLL on the target machine. The application loads the DLL and gives the attacker access at the same privilege level as the application.

Vendors
vyaire
Products
carefusion upgrade utility
Weakness
CWE-427
Vector
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.