DLL Hijacking in InternetSoft FTP Commander Affected by Untrusted Search Path
CVE-2017-11749
7.8HIGH
What is CVE-2017-11749?
InternetSoft FTP Commander versions 8.02 and earlier exhibit a vulnerability due to an untrusted search path, which can be exploited for DLL hijacking. This allows an attacker to place a malicious dwmapi.dll file in a location that the application will load, leading to unauthorized code execution. Users of affected versions should ensure they update to the latest version to mitigate this risk.
