The following table lists the changes that have been made to the
CVE-2024-42048 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.
-
New CVE Received
by [email protected]Aug. 07, 2025
Action Type Old Value New Value Added Description OpenOrange Business Framework 1.15.5 provides unprivileged users with write access to the installation directory. Added Reference https://attack.mitre.org/techniques/T1574/001 Added Reference https://docs.microsoft.com/en-us/windows/win32/api/libloaderapi/nf-libloaderapi-loadlibrarya Added Reference https://docs.microsoft.com/en-us/windows/win32/api/libloaderapi/nf-libloaderapi-loadlibraryexa Added Reference https://docs.microsoft.com/en-us/windows/win32/dlls/dynamic-link-library-search-order Added Reference https://landings.openorange.com/l/erp-peru-a.html Added Reference https://raw.githubusercontent.com/securityadvisories/Security-Advisories/refs/heads/main/Advisories/Blaze%20Information%20Security%20-%20DLL%20Hijacking%20in%20OpenOrange%20Business%20Framework%20Allows%20Arbitrary%20Code%20Execution%20and%20Potential%20Privilege%20Escalation.txt Added Reference https://resources.infosecinstitute.com/topic/dll-hijacking Added Reference https://support.microsoft.com/en-us/topic/secure-loading-of-libraries-to-prevent-dll-preloading-attacks-d41303ec-0748-9211-f317-2edc819682e1 Added Reference https://www.openorange.com