CVE-2018-6461 Information
Feb 14, 2021
cve
Description
March Hare WINCVS before 2.8.01 build 6610 and CVS Suite before 2009R2 build 6610 contains an Insecure Library Loading vulnerability in the wincvs2.exe or wincvs.exe file which may allow local users to gain privileges via a Trojan horse Python or TCL DLL file in the current working directory.
CVSS Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Reference
http://hyp3rlinx.altervista.org/advisories/CVS-SUITE-2009R2-INSECURE-LIBRARY-LOADING-CVE-2018-6461.txt http://march-hare.com/cvspro/vulnwincvs.htm http://packetstormsecurity.com/files/146267/WINCVS-2009R2-DLL-Hijacking.html http://seclists.org/fulldisclosure/2018/Feb/24
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
7.8
Share on: