HomeSecurityDLL vulnerability fixed in Telerik Analytics Monitor Library

DLL vulnerability fixed in Telerik Analytics Monitor Library

A vulnerability in some versions of Telerik Analytics Monitor Library can be exploited by uploading a malicious DLL assembly.

 

DLL glitch - Telerik Analytics Monitor Library

A vulnerability in certain versions of the TeΙerik Analytics Monitor Library can be exploited to allow access to components of an industrial control system (ICS), causing the application to download a malicious set of DLL files.

The library offers Analytics application services and is integrated with other software solutions (such as Elipse) used in ICS environments. Its purpose is to collect metrics for vendors.

Security researcher Ivan Javier Sanchez from Nullcode Team in Argentina, which focuses on ICS and SCADA research, discovered the vulnerability after detecting a process control issue in the Telerik product.

The vulnerability exists in version 3.2.96 of the library, released on August 3, 2014, when hardware support was included in the TeΙerik custom version of the OpenSSL cryptographic library.

OpenSSL is used to encrypt information collected from the machine during transmission to the vendor. In the problematic app analytics review, four cryptography DLLs, not distributed by Telerik, are loaded at runtime.

According to a security advisory from Carnegie Mellon University CERT, an attacker could exploit the vulnerability and provide malicious DLL files that are to be loaded into the context of the Telerik-based application.

“The Telerik Analytics Monitor Library has been used in industrial control systems (ICS), which could lead to access to the ICS if the vulnerability is exploited,” the security bulletin explains.

The vulnerability has not been assigned a CVE number , but CERT calculated a severity score based on the Common Vulnerability Scoring System (CVSS) and assigned a score of 6.2.

Telerik has released version 3.2.125 of the library, which fixes the security flaw by disabling hardware support in OpenSSLso that third-party DLLs are not loaded.

However, version 3.2.129 is recommended, which incorporates an additional security fix for a regression bug.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS