CVE-2024-7886

A vulnerability has been found in Scooter Software Beyond Compare up to 3.3.5.15075 and classified as critical. Affected by this vulnerability is an unknown functionality in the library 7zxa.dll. The manipulation leads to uncontrolled search path. Attacking locally is a requirement. The real existence of this vulnerability is still doubted at the moment. NOTE: The vendor explains that a system must be breached before exploiting this issue.
Configurations

No configuration.

History

19 Aug 2024, 13:00

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad ha sido encontrada en Scooter Software Beyond Compare hasta 3.3.5.15075 y clasificada como crítica. Una función desconocida en la librería 7zxa.dll es afectada por esta vulnerabilidad. La manipulación conduce a una ruta de búsqueda incontrolada. Atacar localmente es un requisito. Por el momento todavía se duda de la existencia real de esta vulnerabilidad. NOTA: El proveedor explica que se debe vulnerar un sistema antes de explotar este problema.

17 Aug 2024, 08:15

Type Values Removed Values Added
Summary (en) ** DISPUTED ** A vulnerability has been found in Scooter Software Beyond Compare up to 3.3.5.15075 and classified as critical. Affected by this vulnerability is an unknown functionality in the library 7zxa.dll. The manipulation leads to uncontrolled search path. Attacking locally is a requirement. The real existence of this vulnerability is still doubted at the moment. NOTE: The vendor explains that a system must be breached before exploiting this issue. (en) A vulnerability has been found in Scooter Software Beyond Compare up to 3.3.5.15075 and classified as critical. Affected by this vulnerability is an unknown functionality in the library 7zxa.dll. The manipulation leads to uncontrolled search path. Attacking locally is a requirement. The real existence of this vulnerability is still doubted at the moment. NOTE: The vendor explains that a system must be breached before exploiting this issue.

16 Aug 2024, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-16 22:15

Updated : 2024-08-19 13:00


NVD link : CVE-2024-7886

Mitre link : CVE-2024-7886

CVE.ORG link : CVE-2024-7886


JSON object : View

Products Affected

No product.

CWE
CWE-427

Uncontrolled Search Path Element