DLL Hijacking Vulnerabilities During Installation of LG Electronics Software
Published Sep 14, 2020
5.6
MEDIUMCVSS 3.1
EPSS 0.19%
Description
A vulnerability that can hijack a DLL file that is loaded during products(LGPCSuite_Setup, IPSFULLHD, LG_ULTRAWIDE, ULTRA_HD_Driver Setup) installation into a DLL file that the hacker wants. Missing Support for Integrity Check vulnerability in ____COMPONENT____ of LG Electronics (LGPCSuite_Setup), (IPSFULLHD, LG_ULTRAWIDE, ULTRA_HD_Driver Setup) allows ____ATTACKER/ATTACK____ to cause ____IMPACT____. This issue affects: LG Electronics; LGPCSuite_Setup : 1.0.0.3 on Windows(x86, x64); IPSFULLHD, LG_ULTRAWIDE, ULTRA_HD_Driver Setup : 1.0.0.9 on Windows(x86, x64).
Affected products
-
- Version IPSFULLHD, LG_ULTRAWIDE, ULTRA_HD_Driver Setup.exe 1.0.0.3StatusaffectedConstraints-
- Version LGPCSuite_Setup.exe 1.0.0.9StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| LG Electronics | n/a | n/a |
|
- 1.0.0.3
- 1.0.0.3
- 1.0.0.9
- 1.0.0.3
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-28739 Advisory
- https://lgsecurity.lge.com/ x_refsource_MISCVendor Advisory
- https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=35587 x_refsource_MISCThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-28739 | Advisory | |
| https://lgsecurity.lge.com/ | x_refsource_MISCVendor Advisory | |
| https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=35587 | x_refsource_MISCThird Party Advisory |
Change history (0)
No recorded changes yet.