Arbitrary Code Execution Vulnerability in IBM Aspera Connect
CVE-2020-4545

7.8HIGH

Key Information:

Vendor
IBM
Vendor
CVE Published:
4 September 2020

Summary

IBM Aspera Connect version 3.9.9 is susceptible to a vulnerability that allows an attacker to execute arbitrary code on a victim's system. This is due to improper loading of Dynamic Link Libraries (DLLs) by the application's import feature. An attacker can exploit this by convincing the victim to open a specially crafted DLL file, resulting in remote code execution. For more details, you can consult IBM X-Force ID: 183190.

Affected Version(s)

Aspera Connect 3.9.9

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.