First published: Thu Sep 03 2020(Updated: )
IBM Aspera Connect 3.9.9 could allow a remote attacker to execute arbitrary code on the system, caused by improper loading of Dynamic Link Libraries by the import feature. By persuading a victim to open a specially-crafted .DLL file, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 183190.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Aspera Connect | <=3.9.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-4545 is categorized as a critical vulnerability, allowing remote code execution on affected systems.
To fix CVE-2020-4545, update IBM Aspera Connect to the latest version beyond 3.9.9 to eliminate the vulnerability.
CVE-2020-4545 affects IBM Aspera Connect versions up to and including 3.9.9.
CVE-2020-4545 is a remote code execution vulnerability facilitated through improper loading of Dynamic Link Libraries.
An attacker can exploit CVE-2020-4545 by convincing a victim to open a specially-crafted .DLL file.