vendor:
Silo
by:
Unknown
7.5
CVSS
HIGH
Arbitrary Code Execution
Unknown
CWE
Product Name: Silo
Affected Version From: Silo 2.1.1
Affected Version To: Unknown
Patch Exists: NO
Related CWE: Unknown
CPE: Unknown
Platforms Tested: Unknown
Unknown
Arbitrary Code Execution in Silo
The Silo application is vulnerable to an arbitrary code execution vulnerability. This can be exploited by an attacker by tricking a legitimate user into using the vulnerable application to open a file from a network share location that contains a specially crafted Dynamic Link Library (DLL) file. When the DLL file is loaded, the attacker's code is executed.
Mitigation:
Unknown