CVE-2024-30117: HCL BigFix Platform is affected by a DLL Hijack vulnerability
A dynamic search for a prerequisite library could allow the possibility for an attacker to replace the correct file under some circumstances.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-30117?
The severity of CVE-2024-30117 is significant due to the potential for an attacker to replace the correct prerequisite library file.
How do I fix CVE-2024-30117?
To fix CVE-2024-30117, ensure you update your HCLtech Bigfix Platform to a version that is beyond the vulnerable ranges specified in the CVE.
Which versions of HCLtech Bigfix Platform are affected by CVE-2024-30117?
CVE-2024-30117 affects HCLtech Bigfix Platform versions between 9.5 and 10.0.12, as well as versions up to 11.0.3.
What type of vulnerability is CVE-2024-30117?
CVE-2024-30117 is a vulnerability that involves a dynamic search mechanism that could be exploited to replace necessary library files.
How can an attacker exploit CVE-2024-30117?
An attacker could exploit CVE-2024-30117 by leveraging the dynamic search for prerequisite libraries to insert malicious files.