CVE-2020-6789: Uncontrolled Search Path Element in Bosch Monitor Wall Installer
Loading a DLL through an Uncontrolled Search Path Element in the Bosch Monitor Wall installer up to and including version 10.00.0164 potentially allows an attacker to execute arbitrary code on a victim's system. A prerequisite is that the victim is tricked into placing a malicious DLL in the same directory where the installer is started from.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability CVE-2020-6789?
CVE-2020-6789 is a vulnerability in the Bosch Monitor Wall installer up to and including version 10.00.0164 that allows an attacker to execute arbitrary code on a victim's system.
How severe is CVE-2020-6789?
CVE-2020-6789 has a severity rating of 7.8 (high).
What software versions are affected by CVE-2020-6789?
The Bosch Monitor Wall installer up to and including version 10.00.0164 is affected by CVE-2020-6789.
Can CVE-2020-6789 be exploited remotely?
Yes, CVE-2020-6789 can be exploited remotely by tricking the victim into placing a malicious DLL in the same directory.
Is there a fix available for CVE-2020-6789?
It is recommended to update to a version of Bosch Monitor Wall installer higher than 10.00.0164 to mitigate the vulnerability.