Vulnerability Description
ShowMyPC 3606 on Windows suffers from a DLL hijack vulnerability. If an attacker overwrites the file %temp%\ShowMyPC\-ShowMyPC3606\wodVPN.dll, it will run any malicious code contained in that file. The code will run with normal user privileges unless the user specifically runs ShowMyPC as administrator.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Showmypc | Showmypc | 3606 |
| Microsoft | Windows | - |
Related Weaknesses (CWE)
References
- http://showmypc.comProductVendor Advisory
- https://f20.be/cves/showmypc-cve-2021-42923Third Party Advisory
- http://showmypc.comProductVendor Advisory
- https://f20.be/cves/showmypc-cve-2021-42923Third Party Advisory
FAQ
What is CVE-2021-42923?
CVE-2021-42923 is a vulnerability with a CVSS score of 7.3 (HIGH). ShowMyPC 3606 on Windows suffers from a DLL hijack vulnerability. If an attacker overwrites the file %temp%\ShowMyPC\-ShowMyPC3606\wodVPN.dll, it will run any malicious code contained in that file. Th...
How severe is CVE-2021-42923?
CVE-2021-42923 has been rated HIGH with a CVSS base score of 7.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-42923?
Check the references section above for vendor advisories and patch information. Affected products include: Showmypc Showmypc, Microsoft Windows.