CVE-2023-29444 - CVE House
Back to Database
Status published Medium CVE-2023-29444

Uncontrolled Search Path Element in PTC's Kepware KEPServerEX

Vulnerability Description

An uncontrolled search path element vulnerability (DLL hijacking) has been discovered that could allow a locally authenticated adversary to escalate privileges to SYSTEM. Alternatively, they could host a trojanized version of the software and trick victims into downloading and installing their malicious version to gain initial access and code execution.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-29444

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Sam Hanson of Dragos

Affected Vendor

Affected Software

Kepware KEPServerEX, ThingWorx Kepware Server, ThingWorx Industrial Connectivity
Vulnerable Versions:
0, 8.0

Timeline

Official Publish: January 10th, 2024
Last Modified: May 14th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H

Weaknesses (CWE)