CVE-2022-47636: High severity Outsystems Service Studio vulnerability
A DLL hijacking vulnerability has been discovered in OutSystems Service Studio 11 11.53.30 build 61739. When a user open a .oml file (OutSystems Modeling Language), the application will load the following DLLs from the same directory avlibGLESv2.dll, libcef.DLL, user32.dll, and d3d10warp.dll. Using a crafted DLL, it is possible to execute arbitrary code in the context of the current logged in user.
Credit
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-47636?
CVE-2022-47636 is a DLL hijacking vulnerability discovered in OutSystems Service Studio 11 version 11.53.30 build 61739.
How does the DLL hijacking vulnerability in OutSystems Service Studio 11 version 11.53.30 build 61739 work?
When a user opens a .oml file in OutSystems Service Studio 11 version 11.53.30 build 61739, the application loads certain DLLs from the same directory, which can be exploited.
What is the severity of CVE-2022-47636?
The severity of CVE-2022-47636 is high, with a CVSS score of 7.8.
How can I fix the DLL hijacking vulnerability in OutSystems Service Studio 11 version 11.53.30 build 61739?
To fix the DLL hijacking vulnerability, update OutSystems Service Studio to a version that does not have this vulnerability.
Where can I find more information about CVE-2022-47636?
You can find more information about CVE-2022-47636 at the following references: [1] [2].