Uncontrolled Search Path Element in PTC's Kepware KEPServerEX
CVE-2023-29444
Key Information:
- Vendor
Ptc
- Vendor
- CVE Published:
- 10 January 2024
What is CVE-2023-29444?
A vulnerability has been identified in select PTC software products, allowing an authenticated local attacker to exploit an uncontrolled search path element, also known as DLL hijacking. This flaw could be leveraged to escalate privileges to the SYSTEM level. Additionally, attackers might create and distribute a trojanized version of the affected software, deceiving users into installing it, thereby gaining unauthorized access and executing arbitrary code. Organizations using these PTC products should implement recommended security measures to mitigate potential exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Kepware KEPServerEX Windows 0 <= 6.14.263.0
ThingWorx Industrial Connectivity Windows 8.0 <= 8.5
ThingWorx Kepware Server Windows 0 <= 6.14.263.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
