First published: Fri Jun 22 2012(Updated: )
Untrusted search path vulnerability in IBM Lotus Expeditor 6.1.x and 6.2.x before 6.2 FP5+Security Pack allows local users to gain privileges via a Trojan horse DLL in the current working directory.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Expeditor | =6.1 | |
IBM Expeditor | =6.1.1 | |
IBM Expeditor | =6.2 | |
IBM Expeditor | =6.2.1 | |
IBM Expeditor | =6.2.2 | |
IBM Expeditor | =6.2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-0187 is classified as a high severity vulnerability due to its potential to allow local users to escalate privileges.
To fix CVE-2012-0187, upgrade to IBM Lotus Expeditor version 6.2 FP5 or later with the Security Pack.
CVE-2012-0187 affects IBM Lotus Expeditor versions 6.1.x and 6.2.x prior to 6.2 FP5 with Security Pack.
CVE-2012-0187 cannot be exploited remotely as it requires local user access to the vulnerable system.
CVE-2012-0187 is an untrusted search path vulnerability that allows for execution of malicious DLLs.