CVE-2023-49114

A DLL hijacking vulnerability was identified in the Qognify VMS Client Viewer version 7.1 or higher, which allows local users to execute arbitrary code and obtain higher privileges via careful placement of a malicious DLL, if some specific pre-conditions are met.
References
Link Resource
http://seclists.org/fulldisclosure/2024/Mar/10 Exploit Mailing List Third Party Advisory
https://r.sec-consult.com/qognify Exploit Third Party Advisory
http://seclists.org/fulldisclosure/2024/Mar/10 Exploit Mailing List Third Party Advisory
https://r.sec-consult.com/qognify Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:hexagon:qognify_vms_client_viewer:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-02-26 16:27

Updated : 2025-04-25 19:40


NVD link : CVE-2023-49114

Mitre link : CVE-2023-49114

CVE.ORG link : CVE-2023-49114


JSON object : View

Products Affected

hexagon

  • qognify_vms_client_viewer
CWE
CWE-427

Uncontrolled Search Path Element