CVE-2018-1888

MEDIUM

IBM i Access < 7.1 - Untrusted Search Path via LoadLibrary DLL Hijacking

Title source: llm
STIX 2.1

Description

An untrusted search path vulnerability in IBM i Access for Windows versions 7.1 and earlier on Windows can allow arbitrary code execution via a Trojan horse DLL in the current working directory, related to use of the LoadLibrary function. IBM X-Force ID: 152079.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/106455
Patch, Vendor Advisory x_refsource_confirm
https://www.ibm.com/support/docview.wss?uid=ibm10740233
VDB Entry, Vendor Advisory vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/152079

Scores

CVSS v3 5.3
EPSS 0.0124
EPSS Percentile 65.3%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L

Details

CWE
CWE-426
Status published
Products (1)
ibm/i_access < 7.1
Published Jan 04, 2019
Tracked Since Feb 18, 2026