First published: Tue Aug 01 2017(Updated: )
A vulnerability exists in Schneider Electric's Pro-Face GP Pro EX version 4.07.000 that allows an attacker to execute arbitrary code. Malicious code installation requires an access to the computer. By placing a specific DLL/OCX file, an attacker is able to force the process to load arbitrary DLL and execute arbitrary code in the context of the process.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider Electric Proface GP-Pro EX | =4.07.000 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-9961 is classified as a high-severity vulnerability due to its potential to allow arbitrary code execution.
To mitigate CVE-2017-9961, updating to a patched version of Schneider Electric's Pro-Face GP Pro EX is recommended.
CVE-2017-9961 can lead to unauthorized code execution, compromising system integrity and potentially leading to further attacks.
CVE-2017-9961 affects users of Schneider Electric's Pro-Face GP Pro EX version 4.07.000.
CVE-2017-9961 can be exploited by an attacker with access to the computer who places a malicious DLL/OCX file, prompting the process to load the arbitrary code.