#VU97696 Insecure DLL loading in IBM i - CVE-2024-38330
Published: September 25, 2024
IBM i
IBM Corporation
Description
The vulnerability allows a local user to compromise vulnerable system.
The vulnerability exists due to the unqualified library program call. A local user can place a specially crafted .dll file on a remote SMB fileshare, trick the victim into opening a file, associated with the vulnerable application, and execute arbitrary code on victim's system.