CVE-2020-7807: DLL Hijacking Vulnerabilities During Installation of LG Electronics Software
A vulnerability that can hijack a DLL file that is loaded during products(LGPCSuiteSetup, IPSFULLHD, LGULTRAWIDE, ULTRAHDDriver Setup) installation into a DLL file that the hacker wants. Missing Support for Integrity Check vulnerability in COMPONENT of LG Electronics (LGPCSuiteSetup), (IPSFULLHD, LGULTRAWIDE, ULTRAHDDriver Setup) allows ATTACKER/ATTACK to cause IMPACT. This issue affects: LG Electronics; LGPCSuiteSetup : 1.0.0.3 on Windows(x86, x64); IPSFULLHD, LGULTRAWIDE, ULTRAHDDriver Setup : 1.0.0.9 on Windows(x86, x64).
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-7807?
CVE-2020-7807 is a vulnerability that can hijack a DLL file that is loaded during the installation of LGPCSuite_Setup, IPSFULLHD, LG_ULTRAWIDE, and ULTRA_HD_Driver Setup products.
How does CVE-2020-7807 work?
CVE-2020-7807 allows a hacker to hijack a DLL file during product installation and replace it with a malicious DLL file of their choice.
Which software versions are affected by CVE-2020-7807?
CVE-2020-7807 affects LGPCSuite_Setup version 1.0.0.9, IPSFULLHD version 1.0.0.3, LG_ULTRAWIDE version 1.0.0.3, and ULTRA_HD_Driver Setup version 1.0.0.3.
What is the severity level of CVE-2020-7807?
CVE-2020-7807 has a severity level of 5.5, which is considered medium.
How can I fix CVE-2020-7807?
To fix CVE-2020-7807, it is recommended to update the affected software versions to the latest patched versions provided by LG Electronics.