#VU64474 Insecure DLL loading in AutomationDirect products - CVE-2022-2006
Published: June 17, 2022
C-more EA9-T6CL
C-more EA9-T6CL-R
C-more EA9-T7CL
C-more EA9-T7CL-R
C-more EA9-T8CL
C-more EA9-T10CL
C-more EA9-T10WCL
C-more EA9-T12CL
C-more EA9-T15CL
C-more EA9-T15CL-R
C-more EA9-RHMI
C-more EA9-PGMSW
AutomationDirect
Description
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to the application loads DLL libraries in an insecure manner within the install directory. A remote attacker can place a specially crafted .dll file on a remote SMB fileshare, trick the victim into opening a file, associated with the vulnerable application, and execute arbitrary code on victim's system.