CVE-2024-28099

VT STUDIO Ver.8.32 and earlier contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries. As a result, arbitrary code may be executed with the privileges of the running application.
Configurations

Configuration 1 (hide)

cpe:2.3:a:keyence:vt_studio:*:*:*:*:*:*:*:*

History

30 Jun 2025, 13:50

Type Values Removed Values Added
References () https://jvn.jp/en/vu/JVNVU92825069/ - () https://jvn.jp/en/vu/JVNVU92825069/ - Third Party Advisory
References () https://www.keyence.com/vt_vulnerability240329_en - () https://www.keyence.com/vt_vulnerability240329_en - Vendor Advisory
First Time Keyence
Keyence vt Studio
CPE cpe:2.3:a:keyence:vt_studio:*:*:*:*:*:*:*:*

21 Nov 2024, 09:05

Type Values Removed Values Added
References () https://jvn.jp/en/vu/JVNVU92825069/ - () https://jvn.jp/en/vu/JVNVU92825069/ -
References () https://www.keyence.com/vt_vulnerability240329_en - () https://www.keyence.com/vt_vulnerability240329_en -

08 Aug 2024, 20:35

Type Values Removed Values Added
CWE CWE-427
Summary
  • (es) VT STUDIO Ver.8.32 y anteriores contienen un problema con la ruta de búsqueda de DLL, lo que puede provocar que se carguen bibliotecas de vínculos dinámicos de forma insegura. Como resultado, se puede ejecutar código arbitrario con los privilegios de la aplicación en ejecución.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8

15 Apr 2024, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-15 11:15

Updated : 2025-06-30 13:50


NVD link : CVE-2024-28099

Mitre link : CVE-2024-28099

CVE.ORG link : CVE-2024-28099


JSON object : View

Products Affected

keyence

  • vt_studio
CWE
CWE-427

Uncontrolled Search Path Element