Insecure DLL loading in Password Manager for Windows - CVE-2021-28647

 

Insecure DLL loading in Password Manager for Windows - CVE-2021-28647

Published: March 31, 2021


Vulnerability identifier: #VU51820
CSH Severity: Medium
CVSS v4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-28647
CWE-ID: CWE-427
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to the application loads DLL libraries in an insecure manner during the installation progress. A remote attacker can place a specially crafted .dll file on a remote SMB fileshare, trick the victim into installing the password manager from the remote share and execute arbitrary code on victim's system.


Affected software

Password Manager for Windows

How to mitigate CVE-2021-28647

Install updates from vendor's website.

Password Manager for Windows - update to 5.0.0.1217

External References

Related Security Bulletins