First published: Thu Nov 30 2023(Updated: )
An uncontrolled search path element vulnerability has been found on 4D and 4D server Windows executables applications, affecting version 19 R8 100218. This vulnerability consists in a DLL hijacking by replacing x64 shfolder.dll in the installation path, causing an arbitrary code execution.
Credit: cve-coordination@incibe.es
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Any of | ||
4d 4d | =19-r8 | |
4D Server | =19-r8 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-4770 is an uncontrolled search path element vulnerability found in 4D and 4D Server Windows executables.
The severity of CVE-2023-4770 is high with a CVSS score of 7.8.
CVE-2023-4770 affects 4D and 4D Server executables by allowing DLL hijacking, which can lead to arbitrary code execution.
Version 19 R8 100218 of 4D and 4D Server is affected by CVE-2023-4770.
No, Microsoft Windows is not vulnerable to CVE-2023-4770.
To fix CVE-2023-4770, update to a version of 4D and 4D Server that is not affected by this vulnerability.
You can find more information about CVE-2023-4770 at the following reference: [link](https://www.incibe.es/en/incibe-cert/notices/aviso/uncontrolled-search-path-element-vulnerability-4d-and-4d-windows-server)