CyberRota Analysis
AI-GeneratedThe vulnerability allows an attacker to execute arbitrary code at the victim's privilege level by placing malicious modules alongside a job file, which is executed when the victim interacts with it. This issue affects users of Newell Brands DYMO ID version 1.5.1.71 and should be prioritized by organizations using this software to mitigate potential exploitation risks. Users are strongly advised to upgrade to version 1.6.0, where the vulnerability has been addressed.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Newell Brands DYMO ID 1.5.1.71 resolves its plugin Modules directory relative to the process working directory. An attacker could store a job file alongside malicious modules / DLL that sets the process working directory to the job file's folder when a victim clicks on the file, resulting in code execution at the victim's privilege level. Fixed in 1.6.0.