Insecure DLL loading in Rational Development Studio for i - CVE-2024-25050
Published: May 1, 2024
Rational Development Studio for i
IBM Corporation
Description
The vulnerability allows a local user to compromise vulnerable system.
The vulnerability exists due to the application loads DLL libraries in an insecure manner. A local user can place a specially crafted .dll file on a remote SMB fileshare, trick the victim into opening a file, associated with the vulnerable application, and execute arbitrary code on victim's system.