Uncontrolled Search Path Element in PTC's Kepware KEPServerEX
CVE-2023-29445
7.8HIGH
Key Information:
- Vendor
Ptc
- Vendor
- CVE Published:
- 10 January 2024
What is CVE-2023-29445?
A vulnerability exists in PTC KEPServerEX due to an uncontrolled search path element, commonly referred to as DLL hijacking. This flaw can be exploited by a locally authenticated attacker, granting them the ability to escalate their privileges to SYSTEM level. When an application executes, it may inadvertently load a malicious dynamic link library (DLL) instead of the intended one. This vulnerability poses risks to system integrity and security, making sensitive data and critical operations vulnerable to compromise if exploited.
Affected Version(s)
Kepware KEPServerEX Windows 0 <= 6.14.263.0
ThingWorx Industrial Connectivity Windows 8.0 <= 8.5
ThingWorx Kepware Server Windows 0 <= 6.14.263.0