Flexera InstallAnywhere untrusted DLL search path in IBM Tivoli Storage Manager Administration Center - CVE-2016-4560
Published: July 29, 2016
Vulnerability identifier: #VU232
CSH Severity: High
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2016-4560
CWE-ID: CWE-427
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vendor: IBM Corporation
Affected software:
IBM Tivoli Storage Manager Administration Center
IBM Tivoli Storage Manager Administration Center
Detailed vulnerability description
The vulnerability allows a local userr to obtain elevated privileges on the target system.
The vulnerability exists due to an untrusted search path. A local user can gain elevated privileges on the system using a Trojan horse DLL in the current working directory of a setup-launcher executable file.
Successful exploitation of this vulnerability may result in arbitrary code execution via local system.
The vulnerability exists due to an untrusted search path. A local user can gain elevated privileges on the system using a Trojan horse DLL in the current working directory of a setup-launcher executable file.
Successful exploitation of this vulnerability may result in arbitrary code execution via local system.
How to mitigate CVE-2016-4560
Install the latest version: 6.3.6.