First published: Tue Aug 04 2015(Updated: )
Untrusted search path vulnerability in Schneider Electric Wonderware System Platform before 2014 R2 Patch 01 allows local users to gain privileges via a Trojan horse DLL in an unspecified directory.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Wonderware System Platform | =r2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-3940 is classified as a local privilege escalation vulnerability.
To fix CVE-2015-3940, users should apply the latest patches for Schneider Electric Wonderware System Platform, specifically the 2014 R2 Patch 01.
CVE-2015-3940 affects local users of Schneider Electric Wonderware System Platform versions prior to 2014 R2 Patch 01.
CVE-2015-3940 is an untrusted search path vulnerability that allows exploitation via a Trojan horse DLL.
No, CVE-2015-3940 requires local access to the system to exploit the vulnerability.