Unquoted Windows search path vulnerability in Schneider Electric Floating License Manager 1.0.0 through 1.4.0 allows local users to gain privileges via a Trojan horse application with a name composed of an initial substring of a path that contains a space character.
References
Link | Resource |
---|---|
http://download.schneider-electric.com/files?p_Doc_Ref=SEVD%202014-015-01 | Vendor Advisory |
https://www.cisa.gov/news-events/ics-advisories/icsa-14-058-01 | |
http://download.schneider-electric.com/files?p_Doc_Ref=SEVD%202014-015-01 | Vendor Advisory |
http://ics-cert.us-cert.gov/advisories/ICSA-14-058-01 | US Government Resource |
Configurations
Configuration 1 (hide)
|
History
19 Sep 2025, 19:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
CWE | CWE-428 |
21 Nov 2024, 02:02
Type | Values Removed | Values Added |
---|---|---|
References | () http://download.schneider-electric.com/files?p_Doc_Ref=SEVD%202014-015-01 - Vendor Advisory | |
References | () http://ics-cert.us-cert.gov/advisories/ICSA-14-058-01 - US Government Resource |
Information
Published : 2014-02-28 06:18
Updated : 2025-09-19 19:15
NVD link : CVE-2014-0759
Mitre link : CVE-2014-0759
CVE.ORG link : CVE-2014-0759
JSON object : View
Products Affected
schneider-electric
- floating_license_manager
CWE