An uncontrolled search path element vulnerability has been found on 4D and 4D server Windows executables applications, affecting version 19 R8 100218. This vulnerability consists in a DLL hijacking by replacing x64 shfolder.dll in the installation path, causing an arbitrary code execution.
| Software | From | Fixed in |
|---|---|---|
| 4d / 4d | 19-r8 | 19-r8.x |
| 4d / server | 19-r8 | 19-r8.x |