CVE-2017-5176: High severity rockwell automation connected components workbench vulnerability
A DLL Hijack issue was discovered in Rockwell Automation Connected Components Workbench (CCW). The following versions are affected: Connected Components Workbench - Developer Edition, v9.01.00 and earlier: 9328-CCWDEVENE, 9328-CCWDEVZHE, 9328-CCWDEVFRE, 9328-CCWDEVITE, 9328-CCWDEVDEE, 9328-CCWDEVESE, and 9328-CCWDEVPTE; and Connected Components Workbench - Free Standard Edition (All Supported Languages), v9.01.00 and earlier. Certain DLLs included with versions of CCW software can be potentially hijacked to allow an attacker to gain rights to a victim's affected personal computer. Such access rights can be at the same or potentially higher level of privileges as the compromised user account, including and up to computer administrator privileges.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-5176?
CVE-2017-5176 is classified as a high-severity vulnerability due to the potential for DLL hijacking.
How do I fix CVE-2017-5176?
To fix CVE-2017-5176, you should upgrade to Connected Components Workbench version 9.02.00 or later.
What software is affected by CVE-2017-5176?
CVE-2017-5176 affects the Rockwell Automation Connected Components Workbench Developer Edition up to version 9.01.00.
What type of vulnerability is CVE-2017-5176?
CVE-2017-5176 is a DLL hijack vulnerability that can allow an attacker to execute arbitrary code.
Who is impacted by CVE-2017-5176?
Users of Rockwell Automation Connected Components Workbench versions 9.01.00 and earlier are impacted by CVE-2017-5176.