CVE-2017-6033: High severity Schneider-electric Interactive Graphical Scada System vulnerability
A DLL Hijacking issue was discovered in Schneider Electric Interactive Graphical SCADA System (IGSS) Software, Version 12 and previous versions. The software will execute a malicious file if it is named the same as a legitimate file and placed in a location that is earlier in the search path.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6033?
CVE-2017-6033 has been assigned a moderate severity rating due to the potential for exploitation via DLL hijacking.
How do I fix CVE-2017-6033?
To mitigate CVE-2017-6033, ensure that trusted application paths are prioritized and rename any potentially malicious files.
Which software versions are affected by CVE-2017-6033?
CVE-2017-6033 affects Schneider Electric Interactive Graphical SCADA System software versions 12 and earlier.
What is DLL Hijacking as related to CVE-2017-6033?
DLL Hijacking in CVE-2017-6033 occurs when a malicious DLL file is executed instead of a legitimate one by placing it in a higher priority search path.
Is there a workaround for CVE-2017-6033?
Yes, users can restrict access to the directories where the vulnerable software looks for DLL files to mitigate the risk associated with CVE-2017-6033.