[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f7Nnp78taXHdwEedzEJ8qbayOmz_VjLxWJZUNPYz_Prk":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":47},"1108afa8-c021-4c80-9c38-12731b4540ef","dll-search-order-hijacking-flaw-found-in-abb-advant-master-software","bac93674-2f27-401b-b4c4-59dc160f6e33","DLL Search Order Hijacking Flaw Found in ABB Advant Master Software","CVE-2025-13162 stems from improper handling of DLL search paths in ABB's Advant Master Online Builder, a classic DLL hijacking vulnerability that allows attackers with local system access to execute arbitrary code by placing a malicious DLL in a location the application searches before the legitimate one. This type of flaw is particularly dangerous in industrial control system (ICS) environments, where software often runs with elevated privileges and endpoints may be difficult to patch quickly. The vulnerability highlights how even trusted, legacy industrial software can harbor foundational coding weaknesses that undermine system integrity. ABB's prompt release of a patch is commendable, but the risk window remains open for any organization that delays applying the update.","**Immediate actions:**\n- Apply ABB's updated version of Advant Master Online Builder immediately to close the CVE-2025-13162 vulnerability.\n- Restrict local system access to only authorized personnel to reduce the attacker's opportunity to exploit the DLL hijacking flaw.\n- Audit directory permissions on systems running the affected software to prevent unauthorized DLL placement.\n\n**Long-term improvements:**\n- Establish a formal ICS\u002FOT patch management process with defined SLAs for critical vendor-released updates.\n- Maintain a comprehensive software inventory of all industrial control system components to accelerate vulnerability identification and response.\n- Enforce application whitelisting on OT endpoints to block unauthorized executables and DLLs from running.\n\n**Detection measures:**\n- Deploy file integrity monitoring (FIM) on directories used by industrial software to detect unexpected DLL additions or modifications.\n- Enable detailed process and DLL load logging on ICS hosts and forward events to a centralized SIEM for anomaly detection.\n- Conduct periodic vulnerability scans against OT\u002FICS assets using ICS-aware scanning tools to identify unpatched systems proactively.",[12,13,14,15,16,17,18,19,20],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 7: Continuous Vulnerability Management","CIS Control 18: Application Software Security","NIST SP 800-82: Guide to ICS Security","NIST SI-2: Flaw Remediation","NIST CM-7: Least Functionality","NIST AC-6: Least Privilege","IEC 62443-3-3: SR 3.2 Malicious Code Protection","MITRE ATT&CK T1574.001: DLL Search Order Hijacking","published","2026-07-14T16:22:17.886559+00:00","2026-07-14T16:22:17.552+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fwww.cisa.gov\u002Fnews-events\u002Fics-advisories\u002Ficsa-26-195-01","abb-advant-master-online-builder-04a893","ABB Advant Master Online Builder",[29,35,41],{"id":30,"name":31,"slug":32,"description":33,"color":34},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":36,"name":37,"slug":38,"description":39,"color":40},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",{"id":42,"name":43,"slug":44,"description":45,"color":46},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",[]]