#VU77190 Untrusted search path in IBM Java SDK - CVE-2019-4732
Published: June 13, 2023
IBM Java SDK
IBM Corporation
Description
The vulnerability allows a local privileged user to execute arbitrary code on the target system.
The vulnerability exists due to DLL search order hijacking in Microsoft Windows client. A local privileged user can trick the victim into opening a specially-crafted file in a compromised folder and execute arbitrary code on the target system.