CVE-2018-5457

CVE-2018-5457

Vendor N/A
Product Vyaire Medical CareFusion Upgrade Utility Vulnerability
Weakness CWE-427
Published February 6, 2018
Last update August 5, 2024

CVSS base score

What the vulnerability does

01Description

A uncontrolled search path element issue was discovered in Vyaire Medical CareFusion Upgrade Utility used with Windows XP systems, Versions 2.0.2.2 and prior versions. A successful exploit of this vulnerability requires the local user to install a crafted DLL on the target machine. The application loads the DLL and gives the attacker access at the same privilege level as the application.

Key dates

02Disclosure timeline

February 6, 2018 CVE published
August 5, 2024 Record updated