CVE-2018-0621: High severity logitech connection utility software vulnerability
Published Jul 26, 2018
·Updated
Untrusted search path vulnerability in LOGICOOL CONNECTION UTILITY SOFTWARE versions before 2.30.9 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Affected Software
1 affected component
Logitech Connection Utility Software<2.30.9
Event History
Jul 26, 2018
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-0621?
CVE-2018-0621 is considered a high severity vulnerability due to the potential for privilege escalation.
2
How do I fix CVE-2018-0621?
To fix CVE-2018-0621, update the Logitech Connection Utility Software to version 2.30.9 or later.
3
What type of attack does CVE-2018-0621 enable?
CVE-2018-0621 enables attackers to execute Trojan horse DLLs, potentially allowing them to gain elevated privileges.
4
Which versions of Logitech Connection Utility Software are affected by CVE-2018-0621?
CVE-2018-0621 affects all versions of Logitech Connection Utility Software prior to 2.30.9.
5
Is there any specific directory involved in the CVE-2018-0621 vulnerability?
The vulnerability involves untrusted search paths that can be exploited if a Trojan horse DLL is placed in an unspecified directory.