Plesk

CVE-2023-4931: Vulnerability in Plesk Installer

Situation

DLL Hijacking vulnerability was discovered in Plesk Installer (for Windows).

Impact

An attacker can create a malicious DLL file and somehow upload it to the target server. If Plesk Installer is launched from the directory where the malicious DLL is located, malicious commands will be executed.

Call to action

The vulnerability was fixed in Plesk Installer 3.0.55. No additional actions are required.

Exit mobile version