Uncontrolled Search Path Element Vulnerability in 4D and 4D Windows Server
CVE-2023-4770

7.8HIGH

Key Information:

Vendor

4D

Vendor
CVE Published:
30 November 2023

What is CVE-2023-4770?

A vulnerability in 4D Server applications running on Windows has been identified, allowing for DLL hijacking. This occurs when a malicious actor replaces the x64 shfolder.dll file within the application's installation path. As a result, unauthorized code can be executed, potentially leading to severe security breaches. Users of the affected 4D Server version 19 R8 100218 should take immediate action to mitigate the risk associated with this vulnerability.

Affected Version(s)

4D Server.exe 19 R8 100218

4D.exe 19 R8 100218

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Alexander Huamán Jaimes (@zanganox)
.