Arbitrary Code Execution Vulnerability in IBM Aspera Connect
CVE-2020-4545
7.8HIGH
What is CVE-2020-4545?
IBM Aspera Connect version 3.9.9 is susceptible to a vulnerability that allows an attacker to execute arbitrary code on a victim's system. This is due to improper loading of Dynamic Link Libraries (DLLs) by the application's import feature. An attacker can exploit this by convincing the victim to open a specially crafted DLL file, resulting in remote code execution. For more details, you can consult IBM X-Force ID: 183190.
Affected Version(s)
Aspera Connect 3.9.9