Vulnerability Details CVE-2018-7799
A DLL hijacking vulnerability exists in Schneider Electric Software Update (SESU), all versions prior to V2.2.0, which could allow an attacker to execute arbitrary code on the targeted system when placing a specific DLL file.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 37.5%
CVSS Severity
CVSS v3 Score 7.8
CVSS v2 Score 9.3
Products affected by CVE-2018-7799
-
cpe:2.3:a:schneider-electric:software_update_utility:1.0
-
cpe:2.3:a:schneider-electric:software_update_utility:1.0.13
-
cpe:2.3:a:schneider-electric:software_update_utility:1.1
-
cpe:2.3:a:schneider-electric:software_update_utility:1.2.0
-
cpe:2.3:a:schneider-electric:software_update_utility:1.3.0
-
cpe:2.3:a:schneider-electric:software_update_utility:1.3.1
-
cpe:2.3:a:schneider-electric:software_update_utility:2.0.0