CVE-2024-7326

A vulnerability classified as critical has been found in IObit DualSafe Password Manager 1.4.0.3. This affects an unknown part in the library RTL120.BPL of the component BPL Handler. The manipulation leads to uncontrolled search path. It is possible to launch the attack on the local host. The identifier VDB-273249 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
References
Link Resource
https://lab52.io/blog/dll-side-loading-through-iobit-against-colombia/ Exploit Third Party Advisory
https://vuldb.com/?ctiid.273249 Permissions Required Third Party Advisory
https://vuldb.com/?id.273249 Permissions Required Third Party Advisory
https://vuldb.com/?submit.378150 Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:itopvpn:dualsafe_password_manager:1.4.0.3:*:*:*:*:*:*:*

History

15 Aug 2024, 19:03

Type Values Removed Values Added
References () https://lab52.io/blog/dll-side-loading-through-iobit-against-colombia/ - () https://lab52.io/blog/dll-side-loading-through-iobit-against-colombia/ - Exploit, Third Party Advisory
References () https://vuldb.com/?ctiid.273249 - () https://vuldb.com/?ctiid.273249 - Permissions Required, Third Party Advisory
References () https://vuldb.com/?id.273249 - () https://vuldb.com/?id.273249 - Permissions Required, Third Party Advisory
References () https://vuldb.com/?submit.378150 - () https://vuldb.com/?submit.378150 - Third Party Advisory
First Time Itopvpn
Itopvpn dualsafe Password Manager
CPE cpe:2.3:a:itopvpn:dualsafe_password_manager:1.4.0.3:*:*:*:*:*:*:*

01 Aug 2024, 12:42

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad ha sido encontrada en IObit DualSafe Password Manager 1.4.0.3 y clasificada como crítica. Una función desconocida en la librería RTL120.BPL del componente BPL Handler afecta a una función desconocida. La manipulación conduce a una ruta de búsqueda incontrolada. Es posible lanzar el ataque al servidor local. A esta vulnerabilidad se le asignó el identificador VDB-273249. NOTA: Se contactó al proveedor tempranamente sobre esta divulgación, pero no respondió de ninguna manera.

31 Jul 2024, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-31 21:15

Updated : 2024-08-15 19:03


NVD link : CVE-2024-7326

Mitre link : CVE-2024-7326

CVE.ORG link : CVE-2024-7326


JSON object : View

Products Affected

itopvpn

  • dualsafe_password_manager
CWE
CWE-427

Uncontrolled Search Path Element