CVE-2024-7326

A vulnerability classified as critical has been found in IObit DualSafe Password Manager 1.4.0.3. This affects an unknown part in the library RTL120.BPL of the component BPL Handler. The manipulation leads to uncontrolled search path. It is possible to launch the attack on the local host. The identifier VDB-273249 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
References
Link Resource
https://lab52.io/blog/dll-side-loading-through-iobit-against-colombia/ Exploit Third Party Advisory
https://vuldb.com/?ctiid.273249 Permissions Required Third Party Advisory
https://vuldb.com/?id.273249 Permissions Required Third Party Advisory
https://vuldb.com/?submit.378150 Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:itopvpn:dualsafe_password_manager:1.4.0.3:*:*:*:*:*:*:*

History

15 Aug 2024, 19:03

Type Values Removed Values Added
References () https://lab52.io/blog/dll-side-loading-through-iobit-against-colombia/ - () https://lab52.io/blog/dll-side-loading-through-iobit-against-colombia/ - Exploit, Third Party Advisory
References () https://vuldb.com/?ctiid.273249 - () https://vuldb.com/?ctiid.273249 - Permissions Required, Third Party Advisory
References () https://vuldb.com/?id.273249 - () https://vuldb.com/?id.273249 - Permissions Required, Third Party Advisory
References () https://vuldb.com/?submit.378150 - () https://vuldb.com/?submit.378150 - Third Party Advisory
First Time Itopvpn
Itopvpn dualsafe Password Manager
CPE cpe:2.3:a:itopvpn:dualsafe_password_manager:1.4.0.3:*:*:*:*:*:*:*

01 Aug 2024, 12:42

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-31 21:15

Updated : 2024-08-15 19:03


NVD link : CVE-2024-7326

Mitre link : CVE-2024-7326

CVE.ORG link : CVE-2024-7326


JSON object : View

Products Affected

itopvpn

  • dualsafe_password_manager
CWE
CWE-427

Uncontrolled Search Path Element