Skip to main content

ThinkVantage Access Connections Insecure Library Loading Vulnerability

Last Update Date: 14 Aug 2013 15:49 Release Date: 14 Aug 2013 3763 Views

RISK: High Risk

TYPE: Clients - Productivity Products

TYPE: Productivity Products

A vulnerability has been discovered in ThinkVantage Access Connections, which can be exploited by malicious people to compromise a user's system.

 

The vulnerability is caused due to the application loading libraries (mfc71enu.dll and mfc71loc.dll) in an insecure manner. This can be exploited to load arbitrary libraries by tricking a user into e.g. opening a LOC file located on a remote WebDAV or SMB share.

 

Successful exploitation allows execution of arbitrary code.

 

Note: No official solution is currently available. 


Impact

  • Remote Code Execution

System / Technologies affected

  • version 6.01

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • No official solution is currently available.

Vulnerability Identifier

  • No CVE information is available

Source


Related Link