CVE-2018-16545

UnknownEPSS 1.70%

Last modified

CVE-2018-16545 is a vulnerability of currently unknown severity. Kaizen Asset Manager (Enterprise Edition) and Training Manager (Enterprise Edition) allow a remote attacker to achieve arbitrary code execution via file impersonation. For example, a malicious dynamic-link library (dll) assumed the identity of a temporary (tmp) file (isxdl.dll) and an executable file assumed the identity of a temporary file (996E.temp).. EPSS estimates a 1.70% chance of exploitation in the next 30 days.

Description

Kaizen Asset Manager (Enterprise Edition) and Training Manager (Enterprise Edition) allow a remote attacker to achieve arbitrary code execution via file impersonation. For example, a malicious dynamic-link library (dll) assumed the identity of a temporary (tmp) file (isxdl.dll) and an executable file assumed the identity of a temporary file (996E.temp).

Metrics

EPSS Probability
1.70%

74.3th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
KzsoftwareAsset Manager<= 1.0.1188.0
KzsoftwareTraining Manager<= 1.0.1230.0

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2018-16545?
Kaizen Asset Manager (Enterprise Edition) and Training Manager (Enterprise Edition) allow a remote attacker to achieve arbitrary code execution via file impersonation. For example, a malicious dynamic-link library (dll) assumed the identity of a temporary (tmp) file (isxdl.dll) and an executable file assumed the identity of a temporary file (996E.temp).
How severe is CVE-2018-16545?
Severity scoring for CVE-2018-16545 is pending analysis. The EPSS model estimates a 1.70% probability of exploitation in the next 30 days.
How do I fix CVE-2018-16545?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2018-16545?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST