Sep 3, 2020 8:00 pm EDT
Categorized: High Severity
Share this post:
IBM Aspera Connect could allow a remote attacker to execute arbitrary code on the system, caused by improper loading of Dynamic Link Libraries by the import feature. By persuading a victim to open a specially-crafted .DLL file, an attacker could exploit this vulnerability to execute arbitrary code on the system.
Affected product(s) and affected version(s):
Affected Product(s) | Version(s) |
IBM Aspera Connect | 3.9.9 and earlier |
Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: https://www.ibm.com/support/pages/node/6326537
from IBM Product Security Incident Response Team https://ift.tt/3hYKJfA
No comments:
Post a Comment
Note: Only a member of this blog may post a comment.