CVE-2018-6765 Information
Feb 14, 2021
cve
Description
Swisscom MySwisscomAssistant 2.17.1.1065 contains a vulnerability that could allow an unauthenticated remote attacker to execute arbitrary code on the targeted system. This vulnerability exists due to the way .dll files are loaded. It allows an attacker to load a .dll of the attacker’s choosing that could execute arbitrary code without the user’s knowledge. The specific flaw exists within the handling of several DLLs (dwmapi.dll IPHLPAPI.DLL WindowsCodecs.dll RpcRtRemote.dll CRYPTSP.dll rasadhlp.dll DNSAPI.dll ntmarta.dll netbios.dll olepro32.dll security.dll winhttp.dll WINSTA.dll) loaded by the MySwisscomAssistant_Setup.exe process.
CVSS Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Reference
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
7.8
Share on: