CVE-2022-47636 is a DLL hijacking vulnerability affecting OutSystems Service Studio 11, specifically version 11.53.30 build 61739. This flaw allows an attacker to execute arbitrary code by crafting malicious DLLs (av_libGLESv2.dll, libcef.DLL, user32.dll, or d3d10warp.dll) in the same directory as a legitimate .oml file, which are then loaded when a user opens the file. Rated with a CVSS score of 7.8 (HIGH), the vulnerability requires user interaction (UI:R) but has low attack complexity (AC:L) and can lead to complete compromise of confidentiality, integrity, and availability (C:H/I:H/A:H) in the context of the current user. While not currently on the KEV catalog or showing active exploitation, a public exploit is available on ExploitDB (EDB-51678), though there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11.53.30CPE matchmatch criteria | cpe:2.3:a:outsystems:service_studio:11.53.30:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.