DLL Hijacking Vulnerability in OutSystems Service Studio by OutSystems
CVE-2022-47636

7.8HIGH

Key Information:

Vendor

Outsystems

Vendor
CVE Published:
10 August 2023

What is CVE-2022-47636?

A DLL hijacking vulnerability exists in OutSystems Service Studio 11.53.30, allowing local attackers to exploit the application. When users open a .oml file, the application may load malicious DLLs from the same directory, such as av_libGLESv2.dll, libcef.DLL, user32.dll, and d3d10warp.dll. If crafted specifically, these DLLs can execute arbitrary code in the context of the user, potentially leading to unauthorized actions or access to sensitive data.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.