First published: Wed Mar 24 2021(Updated: )
Loading a DLL through an Uncontrolled Search Path Element in the Bosch Monitor Wall installer up to and including version 10.00.0164 potentially allows an attacker to execute arbitrary code on a victim's system. A prerequisite is that the victim is tricked into placing a malicious DLL in the same directory where the installer is started from.
Credit: psirt@bosch.com
Affected Software | Affected Version | How to fix |
---|---|---|
Bosch Monitor Wall | <=10.00.0164 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-6789 is a vulnerability in the Bosch Monitor Wall installer up to and including version 10.00.0164 that allows an attacker to execute arbitrary code on a victim's system.
CVE-2020-6789 has a severity rating of 7.8 (high).
The Bosch Monitor Wall installer up to and including version 10.00.0164 is affected by CVE-2020-6789.
Yes, CVE-2020-6789 can be exploited remotely by tricking the victim into placing a malicious DLL in the same directory.
It is recommended to update to a version of Bosch Monitor Wall installer higher than 10.00.0164 to mitigate the vulnerability.