CVE-2019-5958: High severity soumu electronic reception and examination of application for radio licenses vulnerability
Untrusted search path vulnerability in Electronic reception and examination of application for radio licenses Offline 1.0.9.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Affected Software
Event History
Frequently Asked Questions
What must an attacker do to exploit this issue?
An attacker must place a Trojan horse DLL in an unspecified directory that the affected application searches when loading libraries. Exploitation also requires a user to interact with the application, as reflected by the CVSS user-interaction requirement.
Is remote exploitation indicated by the available CVSS data?
No. The CVSS vector identifies local attack access, so the available data indicates the attacker needs local access rather than network-only reachability.
Which installations are known to be affected?
Electronic reception and examination of application for radio licenses Offline version 1.0.9.0 and earlier is identified as affected. The provided data does not state whether any particular installation configuration is exempt.