CVE-2024-12530: Insecure Dynamic-Link Library (DLL) Load vulnerability

Published Apr 17, 2025
·
Updated

Uncontrolled Search Path Element vulnerability in OpenText Secure Content Manager on Windows allows DLL Side-Loading.This issue affects Secure Content Manager: 23.4.

End-users can potentially exploit the vulnerability to execute malicious code in the trusted context of the thick-client application.

Affected Software

1 affected component
OpenText Secure Content Manager

Remediation

Information

Loading the Dynamic-Link Libraries (DLLs) using fully qualified paths. Apply one of the following patches depending on the version deployed in your environment Secure Content Manager 23.4 Patch 3: Patch 219857 – Content Manager 23.4 Patch 3 Build 260 Secure Content Manager 23.4 Patch 1 HF 7: HOTFIX30220 – Content Manager 23.4 Patch 1 HF 7 Secure Content Manager 23.4 Patch 2 HF 1: HOTFIX30427 – Content Manager 23.4 Patch 2 HF 1

Event History

Apr 17, 2025
CVE Published
via MITRE·03:35 PM
Data Sourced
via MITRE·03:35 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-12530?

CVE-2024-12530 is classified as a high-severity vulnerability due to the potential for DLL side-loading leading to arbitrary code execution.

2

How do I fix CVE-2024-12530?

To remediate CVE-2024-12530, users should update to the patched version of OpenText Secure Content Manager as provided by the vendor.

3

Who is affected by CVE-2024-12530?

CVE-2024-12530 affects users of OpenText Secure Content Manager version 23.4 on Windows systems.

4

What is DLL Side-Loading in the context of CVE-2024-12530?

DLL Side-Loading refers to the practice of executing malicious DLL files in a trusted application context, which is a risk posed by CVE-2024-12530.

5

Is there a workaround for CVE-2024-12530 before applying a patch?

There are no recommended workarounds for CVE-2024-12530; patching is the preferred method to mitigate the vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203