Description
An Uncontrolled Search Path Element issue was discovered in Trihedral VTScada 11.3.03 and prior. The program will execute specially crafted malicious dll files placed on the target machine.
References (1)
Core 1
Core References
Issue Tracking, Mitigation, Third Party Advisory, US Government Resource x_refsource_misc
https://ics-cert.us-cert.gov/advisories/ICSA-17-304-02
Scores
CVSS v3
7.8
EPSS
0.0093
EPSS Percentile
55.9%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Details
CWE
CWE-427
Status
published
Products (2)
n/a/Trihedral Engineering Limited VTScada
Trihedral Engineering Limited VTScada
trihedral/vtscada
< 11.3.03
Published
Nov 06, 2017
Tracked Since
Feb 18, 2026