CVE-2018-5457
Severity CVSS v4.0:
Pending analysis
Type:
CWE-427
Uncontrolled Search Path Element
Publication date:
06/02/2018
Last modified:
09/10/2019
Description
A uncontrolled search path element issue was discovered in Vyaire Medical CareFusion Upgrade Utility used with Windows XP systems, Versions 2.0.2.2 and prior versions. A successful exploit of this vulnerability requires the local user to install a crafted DLL on the target machine. The application loads the DLL and gives the attacker access at the same privilege level as the application.
Impact
Base Score 3.x
7.00
Severity 3.x
HIGH
Base Score 2.0
6.90
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:vyaire:carefusion_upgrade_utility:*:*:*:*:*:*:*:* | 2.0.2.2 (including) | |
| cpe:2.3:o:microsoft:windows_xp:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



