CVE-2020-7474: High severity Schneider-electric Pmepxm0100 Prosoft Configurator vulnerability
A CWE-427: Uncontrolled Search Path Element vulnerability exists in ProSoft Configurator (v1.002 and prior), for the PMEPXM0100 (H) module, which could cause the execution of untrusted code when using double click to open a project file which may trigger execution of a malicious DLL.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ProSoft Configuratorto a version that resolves this vulnerability.Fixed in v1.002 - Compensating control
For ProSoft Configurator versions v1.002 and prior, avoid using double click to open project files for the PMEPXM0100 (H) module to prevent execution of a malicious DLL.
Event History
Frequently Asked Questions
What user action is required for exploitation?
A user must double-click to open a project file. Opening a project file in this way can trigger loading and execution of a malicious DLL.
Which installations are affected?
The issue affects ProSoft Configurator version 1.002 and earlier when used with the PMEPXM0100 (H) module.
Does exploitation require prior authentication or network access?
The CVSS vector indicates local attack access, no privileges required, and user interaction required. The provided data does not describe a network-based exploitation path.