First published: Wed Dec 24 2014(Updated: )
Multiple untrusted search path vulnerabilities in Huawei eSpace Desktop before V200R003C00 allow local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse (1) mfc71enu.dll, (2) mfc71loc.dll, (3) tcapi.dll, or (4) airpcap.dll.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei eSpace Desktop | <=v200r003c00 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-9416 is considered a moderate severity vulnerability due to its potential for local code execution.
To mitigate CVE-2014-9416, users should update Huawei eSpace Desktop to a version later than V200R003C00.
CVE-2014-9416 can facilitate DLL hijacking attacks, allowing an attacker to execute arbitrary code.
CVE-2014-9416 affects all versions of Huawei eSpace Desktop up to and including V200R003C00.
The vulnerable files in CVE-2014-9416 include mfc71enu.dll, mfc71loc.dll, tcapi.dll, and airpcap.dll.