VYPR
Unrated severityNVD Advisory· Published Sep 7, 2018· Updated Aug 5, 2024

CVE-2018-0649

CVE-2018-0649

Description

Untrusted search path vulnerability in the installers of multiple Canon IT Solutions Inc. software programs (ESET Smart Security Premium, ESET Internet Security, ESET Smart Security, ESET NOD32 Antivirus, DESlock+ Pro, and CompuSec (all programs except packaged ones)) allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

The installers of multiple Canon IT Solutions security products are vulnerable to an untrusted search path attack, allowing arbitrary code execution via a malicious DLL.

Vulnerability

The installers of multiple Canon IT Solutions Inc. security products — including ESET Smart Security Premium, ESET Internet Security, ESET Smart Security, ESET NOD32 Antivirus, DESlock+ Pro, and CompuSec (all programs except packaged ones) — contain an untrusted search path vulnerability (CWE-427) due to an insecure DLL search path [1]. All installer versions with digital timestamps before July 10, 2018 are affected [1].

Exploitation

An attacker must place a specially crafted Trojan horse DLL in an unspecified directory where the installer is executed, such as the same directory as the installer file or the Windows search path [1]. The user must then run the installer with normal user privileges, which triggers the insecure DLL loading sequence [1].

Impact

If the lure DLL is loaded, arbitrary code execution occurs with the privileges of the user invoking the installer [1]. This can lead to full compromise of the affected user’s system, including disclosure, modification, or destruction of data, and installation of further malware [1].

Mitigation

Canon IT Solutions Inc. has provided updated installers with digital timestamps on or after July 10, 2018 that fix the issue [1]. Users should download and use the latest installer from the vendor's official site. As a workaround, users should verify that no suspicious files exist in the directory where the installer resides before executing it [1]. The vulnerability affects only the installer itself; already-installed programs are not at risk [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.