CVE-2023-4770

Severity CVSS v4.0:
Pending analysis
Type:
CWE-427 Uncontrolled Search Path Element
Publication date:
30/11/2023
Last modified:
06/12/2023

Description

An uncontrolled search path element vulnerability has been found on 4D and 4D server Windows executables applications, affecting version 19 R8 100218. This vulnerability consists in a DLL hijacking by replacing x64 shfolder.dll in the installation path, causing an arbitrary code execution.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:4d:4d:19:r8:*:*:*:*:*:*
cpe:2.3:a:4d:server:19:r8:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*