IM
IronMonkey Threat Research

CVE-2017-9961 HIGH

Published: 2017-09-26 | Last Modified: 2026-06-17 | Status: Modified

Description

A vulnerability exists in Schneider Electric's Pro-Face GP Pro EX version 4.07.000 that allows an attacker to execute arbitrary code. Malicious code installation requires an access to the computer. By placing a specific DLL/OCX file, an attacker is able to force the process to load arbitrary DLL and execute arbitrary code in the context of the process.

Additional Descriptions (1)

Existe una vulnerabilidad en la versión 4.07.000 de Pro-Face GP Pro EX de Schneider Electric que permite que un atacante ejecute código arbitrario. Se necesita acceder a un ordenador para instalar el código malicioso. Al ubicar un archivo DLL/OCX específico, un atacante podría forzar que el proceso cargue DLL arbitrarios y ejecute códigos también arbitrarios en el contexto del proceso.

CVSS Metrics

Base Score: 4.6 (MEDIUM)

AV:L/AC:L/Au:N/C:P/I:P/A:P

Access VectorLOCAL
Access ComplexityLOW
AuthenticationNONE
Confidentiality ImpactPARTIAL
Integrity ImpactPARTIAL
Availability ImpactPARTIAL

Source: [email protected]

Type: Primary

Exploitability Score: 3.9

Impact Score: 6.4

Weaknesses

Source Type Description
[email protected] Primary
en NVD-CWE-noinfo

Affected Products

Vendor Product Version Update Type
schneider-electric pro-face_gp_pro_ex 4.07.000 <built-in method update of dict object at 0x7e6107f3bbc0> Application

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:schneider-electric:pro-face_gp_pro_ex:4.07.000:*:*:*:*:*:*:*

References

Notification
Message here