First published: Wed Mar 24 2021(Updated: )
Loading a DLL through an Uncontrolled Search Path Element in the Bosch Configuration Manager installer up to and including version 7.21.0078 potentially allows an attacker to execute arbitrary code on a victim's system. A prerequisite is that the victim is tricked into placing a malicious DLL in the same directory where the installer is started from.
Credit: psirt@bosch.com
Affected Software | Affected Version | How to fix |
---|---|---|
<=7.21.0078 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-6788 is a vulnerability that allows an attacker to execute arbitrary code on a victim's system by loading a DLL through an uncontrolled search path element in the Bosch Configuration Manager installer.
The severity of CVE-2020-6788 is high, with a score of 7.8.
Versions up to and including 7.21.0078 of the Bosch Configuration Manager installer are affected by CVE-2020-6788.
To exploit CVE-2020-6788, an attacker needs to trick the victim into placing a malicious DLL in an uncontrolled search path.
Yes, updating to a version of the Bosch Configuration Manager installer that is not vulnerable, as specified by the vendor, should mitigate CVE-2020-6788.