2025-02-13 19:04:13 +00:00

72 lines
2.4 KiB
JSON

{
"id": "CVE-2023-49114",
"sourceIdentifier": "551230f0-3615-47bd-b7cc-93e92e730bbf",
"published": "2024-02-26T16:27:47.217",
"lastModified": "2025-02-13T18:15:42.940",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "A DLL hijacking vulnerability was identified in the Qognify VMS Client Viewer version 7.1 or higher, which allows local users to execute arbitrary code and obtain higher privileges via careful placement of a malicious DLL, if some\u00a0specific pre-conditions are met."
},
{
"lang": "es",
"value": "Se identific\u00f3 una vulnerabilidad de secuestro de DLL en Qognify VMS Client Viewer versi\u00f3n 7.1 o superior, que permite a los usuarios locales ejecutar c\u00f3digo arbitrario y obtener mayores privilegios mediante la colocaci\u00f3n cuidadosa de un DLL malicioso, si se cumplen algunas condiciones previas espec\u00edficas."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H",
"baseScore": 6.7,
"baseSeverity": "MEDIUM",
"attackVector": "LOCAL",
"attackComplexity": "HIGH",
"privilegesRequired": "LOW",
"userInteraction": "REQUIRED",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH"
},
"exploitabilityScore": 0.8,
"impactScore": 5.9
}
]
},
"weaknesses": [
{
"source": "551230f0-3615-47bd-b7cc-93e92e730bbf",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-427"
}
]
}
],
"references": [
{
"url": "http://seclists.org/fulldisclosure/2024/Mar/10",
"source": "551230f0-3615-47bd-b7cc-93e92e730bbf"
},
{
"url": "https://r.sec-consult.com/qognify",
"source": "551230f0-3615-47bd-b7cc-93e92e730bbf"
},
{
"url": "http://seclists.org/fulldisclosure/2024/Mar/10",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://r.sec-consult.com/qognify",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
]
}