The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric MSX Configurator software prior to V1.0.8.1
- Summary
- A CWE-427:Uncontrolled Search Path Element vulnerability exists which could cause privilege escalation when injecting a malicious DLL.
- Remediation
- This vulnerability is fixed in version V1.0.8.1 MSX Configurator software and is available for download below: https://www.se.com/ww/en/download/document/MSX+Configurator/
