CVE-2018-5457: High severity Vyaire CareFusion Upgrade Utility vulnerability
A uncontrolled search path element issue was discovered in Vyaire Medical CareFusion Upgrade Utility used with Windows XP systems, Versions 2.0.2.2 and prior versions. A successful exploit of this vulnerability requires the local user to install a crafted DLL on the target machine. The application loads the DLL and gives the attacker access at the same privilege level as the application.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Vyaire Medical CareFusion Upgrade Utilityto a version that resolves this vulnerability.Fixed in 2.0.2.2 - Compensating control
On Windows XP systems using Vyaire Medical CareFusion Upgrade Utility (v2.0.2.2 and prior), mitigate uncontrolled search path element DLL planting by ensuring the application’s DLL search path only includes trusted, protected directories (e.g., avoid writable directories and remove untrusted search-path elements).
Event History
Frequently Asked Questions
What is CVE-2018-5457?
CVE-2018-5457 is a vulnerability discovered in Vyaire Medical CareFusion Upgrade Utility used with Windows XP systems, Versions 2.0.2.2 and prior versions.
How does CVE-2018-5457 exploit work?
A successful exploit of CVE-2018-5457 requires the local user to install a crafted DLL on the target machine.
What is the severity of CVE-2018-5457?
CVE-2018-5457 has a high severity rating with a severity value of 7.
Is Microsoft Windows XP vulnerable to CVE-2018-5457?
No, Microsoft Windows XP is not vulnerable to CVE-2018-5457.
How can I fix CVE-2018-5457?
To fix CVE-2018-5457, users should update to a version of Vyaire Medical CareFusion Upgrade Utility that is newer than 2.0.2.2.