CVE-2024-42048 – OpenOrange Business Framework Privilege Escalation

The following table lists the changes that have been made to the
CVE-2024-42048 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Aug. 07, 2025

    Action Type Old Value New Value
    Added Description OpenOrange Business Framework 1.15.5 provides unprivileged users with write access to the installation directory.
    Added Reference https://attack.mitre.org/techniques/T1574/001
    Added Reference https://docs.microsoft.com/en-us/windows/win32/api/libloaderapi/nf-libloaderapi-loadlibrarya
    Added Reference https://docs.microsoft.com/en-us/windows/win32/api/libloaderapi/nf-libloaderapi-loadlibraryexa
    Added Reference https://docs.microsoft.com/en-us/windows/win32/dlls/dynamic-link-library-search-order
    Added Reference https://landings.openorange.com/l/erp-peru-a.html
    Added Reference https://raw.githubusercontent.com/securityadvisories/Security-Advisories/refs/heads/main/Advisories/Blaze%20Information%20Security%20-%20DLL%20Hijacking%20in%20OpenOrange%20Business%20Framework%20Allows%20Arbitrary%20Code%20Execution%20and%20Potential%20Privilege%20Escalation.txt
    Added Reference https://resources.infosecinstitute.com/topic/dll-hijacking
    Added Reference https://support.microsoft.com/en-us/topic/secure-loading-of-libraries-to-prevent-dll-preloading-attacks-d41303ec-0748-9211-f317-2edc819682e1
    Added Reference https://www.openorange.com
Share the Post:

Related Posts