CVE-2018-11551
HIGHAXON PBX 2.02 - Unauthenticated Remote Code Execution via DLL Hijacking
Title source: llmDescription
AXON PBX 2.02 contains a DLL hijacking vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on a targeted system. The vulnerability exists because a DLL file is loaded by 'pbxsetup.exe' improperly.
References (1)
Core 1
Core References
Mailing List, Third Party Advisory mailing-list
x_refsource_fulldisc
http://seclists.org/fulldisclosure/2018/May/69
Scores
CVSS v3
7.8
EPSS
0.0249
EPSS Percentile
82.6%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Details
CWE
CWE-426
Status
published
Products (1)
nch/axon_pbx
2.02
Published
Jun 01, 2018
Tracked Since
Feb 18, 2026