Uncontrolled Search Path Element in PTC's Kepware KEPServerEX
CVE-2023-29444

6.3MEDIUM

What is CVE-2023-29444?

A vulnerability has been identified in select PTC software products, allowing an authenticated local attacker to exploit an uncontrolled search path element, also known as DLL hijacking. This flaw could be leveraged to escalate privileges to the SYSTEM level. Additionally, attackers might create and distribute a trojanized version of the affected software, deceiving users into installing it, thereby gaining unauthorized access and executing arbitrary code. Organizations using these PTC products should implement recommended security measures to mitigate potential exploitation.

Affected Version(s)

Kepware KEPServerEX Windows 0 <= 6.14.263.0

ThingWorx Industrial Connectivity Windows 8.0 <= 8.5

ThingWorx Kepware Server Windows 0 <= 6.14.263.0

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Sam Hanson of Dragos
.