Carrier Block Load Uncontrolled Search Path Element Vulnerability Allowing DLL Hijacking and Arbitrary Code Execution

Vulnerability

A vulnerability has been identified in Carrier Block Load versions 4.00 and 4.10 through 4.16. This vulnerability involves an uncontrolled search path element, which could enable a malicious actor to perform DLL hijacking and execute arbitrary code with escalated privileges.

Impact

Exploitation of this vulnerability could lead to unauthorized execution of code with elevated privileges on the affected system.

Remediation

Users are advised to upgrade to version 4.2 or later. For assistance, contact Carrier's product security team.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
4.7
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.