First published: Wed Mar 24 2021(Updated: )
Loading a DLL through an Uncontrolled Search Path Element in Bosch IP Helper up to and including version 1.00.0008 potentially allows an attacker to execute arbitrary code on a victim's system. A prerequisite is that the victim is tricked into placing a malicious DLL in the same application directory as the portable IP Helper application.
Credit: psirt@bosch.com
Affected Software | Affected Version | How to fix |
---|---|---|
Bosch IP Helper | <=1.00.0008 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-6771 is a vulnerability in Bosch IP Helper up to and including version 1.00.0008 that allows an attacker to execute arbitrary code on a victim's system by loading a DLL through an uncontrolled search path element.
CVE-2020-6771 has a severity score of 7.8, which is considered high.
Bosch IP Helper versions up to and including 1.00.0008 are affected by CVE-2020-6771.
To exploit CVE-2020-6771, an attacker needs to trick the victim into placing a malicious DLL in the same application directory.
There is currently no information available regarding a fix for CVE-2020-6771. It is recommended to follow the vendor's security advisory for updates.