Uncontrolled search path element vulnerability in Plesk Installer affects version 3.27.0.0. A local attacker could execute arbitrary code by injecting DLL files into the same folder where the application is installed, resulting in DLL hijacking in edputil.dll, samlib.dll, urlmon.dll, sspicli.dll, propsys.dll and profapi.dll files.
References
Link | Resource |
---|---|
https://support.plesk.com/hc/en-us/articles/17426121182103 | Vendor Advisory |
https://www.incibe.es/en/incibe-cert/notices/aviso/uncontrolled-search-path-element-vulnerability-plesk | Third Party Advisory |
Configurations
History
01 Dec 2023, 19:06
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
First Time |
Plesk
Plesk plesk |
|
CPE | cpe:2.3:a:plesk:plesk:3.27.0.0:*:*:*:*:*:*:* | |
References | () https://support.plesk.com/hc/en-us/articles/17426121182103 - Vendor Advisory | |
References | () https://www.incibe.es/en/incibe-cert/notices/aviso/uncontrolled-search-path-element-vulnerability-plesk - Third Party Advisory |
30 Nov 2023, 14:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
27 Nov 2023, 14:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-11-27 14:15
Updated : 2024-02-28 20:54
NVD link : CVE-2023-4931
Mitre link : CVE-2023-4931
CVE.ORG link : CVE-2023-4931
JSON object : View
Products Affected
plesk
- plesk
CWE
CWE-427
Uncontrolled Search Path Element