Overview
Telerik Analytics Monitor Library is a third-party application analytics service that collects detailed application metrics for vendors. Some versions of the Telerik library allow DLL hijacking, allowing an attacker to load malicious code in the context of the Telerik-based application.
Description
CWE-114: Process Control Telerik Analytics Monitor Library is supplied as a third-party DLL to be integrated into other software. The library is statically linked with its own build of OpenSSL for supporting HTTPS communication. |
Impact
An attacker could exploit this situation by providing malicious DLLs, allowing the attacker to load malicious code in the context of the Telerik-based application. The Telerik Analytics Monitor Library has been used in Industrial Control Systems (ICS), which may allow significant access to the ICS if the vulnerability is exploited. |
Solution
Apply an update |
Vendor Information (Learn More)
The Telerik Analytics Monitor Library is included with several industrial control systems (ICS). We will list known ICS vendors affected below, along with Telerik. |
Vendor | Status | Date Notified | Date Updated |
---|---|---|---|
Elipse | Affected | - | 11 Mar 2015 |
Telerik | Affected | - | 02 Mar 2015 |
If you are a vendor and your product is affected, let us know.
CVSS Metrics (Learn More)
Group | Score | Vector |
---|---|---|
Base | 6.2 | AV:L/AC:H/Au:N/C:C/I:C/A:C |
Temporal | 4.9 | E:POC/RL:OF/RC:C |
Environmental | 1.2 | CDP:ND/TD:L/CR:ND/IR:ND/AR:ND |
References
- http://www.telerik.com/support/whats-new/analytics/release-history/analytics-monitor-library-3.2.125
- http://www.telerik.com/support/whats-new/analytics/release-history/analytics-monitor-library-v3.2.129
'취약점 정보1' 카테고리의 다른 글
Mozilla Releases Masche Memory Scanning Tool (0) | 2015.03.16 |
---|---|
Maldoc VBA Sandbox/Virtualization Detection (0) | 2015.03.16 |
SSL/TLS implementations accept export-grade RSA keys (FREAK attack) (0) | 2015.03.12 |
Explaining the PostgreSQL pass-the-hash vulnerability (0) | 2015.03.05 |
‘FREAK’ SSL 취약점 주의 권고 (0) | 2015.03.05 |