vendor:
Guitar Rig 4 Player, KONTAKT 4 PLAYER, Service Center, REAKTOR 5 PLAYER
by:
Gjoko 'LiquidWorm' Krstic
7.5
CVSS
HIGH
DLL Hijacking
427
CWE
Product Name: Guitar Rig 4 Player, KONTAKT 4 PLAYER, Service Center, REAKTOR 5 PLAYER
Affected Version From: Guitar Rig 4 Player 4.1.1, KONTAKT 4 PLAYER 4.1.3.4125, Service Center 2.2.5, REAKTOR 5 PLAYER 5.5.1.10584
Affected Version To:
Patch Exists: NO
Related CWE:
CPE: a:nativeinstruments:guitarrig4player:4.1.1.1845, cpe:/a:nativeinstruments:kontakt4player:4.1.3.4125, cpe:/a:nativeinstruments:servicecenter:2.2.5, cpe:/a:nativeinstruments:reaktor5player:5.5.1.10584
Platforms Tested: Microsoft Windows XP Professional SP3
2010
Native Instruments Multiple Products DLL Hijacking Vulnerability
Multiple products from Native Instruments are prone to multiple vulnerabilities that let attackers execute arbitrary code. An attacker can exploit these issues by enticing a legitimate user to use a vulnerable application to open a file from a network share location that contains a specially crafted Dynamic Link Library (DLL) file.
Mitigation:
Update to the latest version of the affected products.