#VU28934 Insecure DLL loading in Siemens products - CVE-2020-7585
Published: June 10, 2020
SIMATIC PCS 7
SIMATIC PDM
SIMATIC STEP 7
SINAMICS STARTER
Siemens
Description
The vulnerability allows a local user to compromise vulnerable system.
The vulnerability exists due to the application loads DLL libraries in an insecure manner. A local user can use a specially crafted .dll file, trick the victim into opening a file, associated with the vulnerable application, and execute arbitrary code on victim's system.