Automation License Manager V6.0 vulnerability

The affected setup component is vulnerable to DLL hijacking. This could allow an attacker to execute arbitrary code when a legitimate user installs an application that uses the affected setup component.

Published 12 Aug 2025Updated 8 Sep 20261 sources
CVSS 8.5

What happened

The affected setup component is vulnerable to DLL hijacking. This could allow an attacker to execute arbitrary code when a legitimate user installs an application that uses the affected setup component.

Affected versions

Automation License Manager V6.0: before * (custom); before V6.2 Upd3 (custom); before V6.9 (custom); before V1.5.5.0 (custom); before V2.0 SP2 (custom); before V5.0 SP4 (custom); before V3.1.0.2 (custom); before V4.1 (custom); before V10.0 SP1 (custom); before V19 Update 4 (custom); before V2.0 Upd3 (custom); before V9.1 SP1 Upd8 (custom); before V2.1 (custom); before V4.1.0.1 (custom); before V5.0.0.1 (custom); before V20.0 Update 1 (custom); before V9.1 SP2 Upd4 (custom); before V9.1 SP2 Upd6 (custom); before V9.1 SP2 Upd2 (custom); before V10.0 SP1 Upd2 (custom); before V9.1 SP2 Upd8 (custom); before V9.1 Upd8 (custom); before V10.0 SP1 UC01 (custom); before V9.1 SP1 UC08 (custom); before V6.0 SP1 (custom); before V9.3 SP1 Upd2 (custom); before V2024 SP1 Upd2 (custom); before V17 Update 9 (custom); before V31.1.5 (custom); before V4.0.1 (custom); before V3.5 SP4 Update 1 (custom); before V7.0 Update 1 (custom); before V20 Update 1 (custom); before V6.0 SP3 (custom); before V21 (custom); before V20 (custom); before V7.5 SP2 Update 20 (custom); before V8.0 Update 8 (custom); before V8.1 Update 3 (custom); before V20 Update 3 (custom); before V4.0 (custom); before V3.1.2.2 (custom); before V3.0.6 (custom); before V2.3 (custom); before V2.2 (custom); before V18 Update 6 (custom); before V20 Update 4 (custom) Fixed: See vendor advisory.

Why it matters

Review the vendor advisory and exposure of the affected product to determine operational impact.

Detection & mitigation

  • Apply vendor-provided updates or mitigations.
  • Review affected product exposure and access logs.

Public PoC references

No public PoC reference has passed the current publication threshold.