CVE-2023-29444
10.01.2024, 17:15
An uncontrolled search path element vulnerability (DLL hijacking) has been discovered that could allow a locally authenticated adversary to escalate privileges to SYSTEM. Alternatively, they could host a trojanized version of the software and trick victims into downloading and installing their malicious version to gain initial access and code execution.Enginsight
Vendor | Product | Version |
---|---|---|
ptc | kepware_kepserverex | 6.0.2107.0 ≤ 𝑥 ≤ 6.14.263.0 |
ptc | thingworx_kepware_server | 6.8 ≤ 𝑥 ≤ 6.14.263.0 |
ptc | thingworx_industrial_connectivity | 8.0 ≤ 𝑥 ≤ 8.5 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration