First published: Thu Jan 15 2015(Updated: )
Multiple untrusted search path vulnerabilities in Corel CAD 2014 allow local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse (1) FxManagedCommands_3.08_9.tx or (2) TD_Mgd_3.08_9.dll file in the current working directory.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Corel Corelcad | =2014 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-8394 is considered a critical vulnerability due to its potential to allow arbitrary code execution.
CVE-2014-8394 allows DLL hijacking by manipulating untrusted search paths that lead to the execution of malicious DLL files.
The files involved in CVE-2014-8394 are FxManagedCommands_3.08_9.tx and TD_Mgd_3.08_9.dll.
Local users of Corel CAD 2014 are affected by CVE-2014-8394.
To mitigate CVE-2014-8394, ensure that you do not run Corel CAD 2014 in environments where untrusted files can be executed.