CVE-2024-7326

HIGH

Itopvpn Dualsafe Password Manager - Uncontrolled Search Path

Title source: rule

Description

A vulnerability classified as critical has been found in IObit DualSafe Password Manager 1.4.0.3. This affects an unknown part in the library RTL120.BPL of the component BPL Handler. The manipulation leads to uncontrolled search path. It is possible to launch the attack on the local host. The identifier VDB-273249 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

Scores

CVSS v3 7.8
EPSS 0.0006
EPSS Percentile 19.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-427
Status published

Affected Products (1)

itopvpn/dualsafe_password_manager

Timeline

Published Jul 31, 2024
Tracked Since Feb 18, 2026