Uncontrolled Search Path Element in PTC's Kepware KEPServerEX
CVE-2023-29445
Key Information:
- Vendor
Ptc
- Vendor
- CVE Published:
- 10 January 2024
What is CVE-2023-29445?
A vulnerability exists in PTC KEPServerEX due to an uncontrolled search path element, commonly referred to as DLL hijacking. This flaw can be exploited by a locally authenticated attacker, granting them the ability to escalate their privileges to SYSTEM level. When an application executes, it may inadvertently load a malicious dynamic link library (DLL) instead of the intended one. This vulnerability poses risks to system integrity and security, making sensitive data and critical operations vulnerable to compromise if exploited.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Kepware KEPServerEX Windows 0 <= 6.14.263.0
ThingWorx Industrial Connectivity Windows 8.0 <= 8.5
ThingWorx Kepware Server Windows 0 <= 6.14.263.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
