CVE-2012-3015
published 2012-07-26CVE-2012-3015: Untrusted search path vulnerability in Siemens SIMATIC STEP7 before 5.5 SP1, as used in SIMATIC PCS7 7.1 SP3 and earlier and other products, allows local users…
PriorityP275medium6.9CVSS 2.0
AVLACMAuNCCICAC
ITWVulnCheck KEV
Exploited in the wild
EPSS
0.46%
36.6th percentile
Untrusted search path vulnerability in Siemens SIMATIC STEP7 before 5.5 SP1, as used in SIMATIC PCS7 7.1 SP3 and earlier and other products, allows local users to gain privileges via a Trojan horse DLL in a STEP7 project folder.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | simatic_pcs7 | <= 7.1 | — |
| siemens | simatic_step_7 | <= 5.5 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect DLL files placed in STEP 7 project folders that are loaded at STEP 7 startup without validation — the attack vector for this CVE (also exploited by Stuxnet). ↗
- →Monitor for DLL loading events originating from STEP 7 project folder paths at application startup, especially unexpected or unsigned DLLs executed with STEP 7 application permissions. ↗
- →This vulnerability is associated with Stuxnet malware; presence of Stuxnet indicators on STEP 7 hosts should be correlated with this DLL hijacking technique. ↗
- →Flag any DLL loaded from a STEP 7 project folder that contains executable code — the patched version explicitly rejects such DLLs. ↗
- ·The exploit is classified as remotely exploitable despite being a local DLL hijack — an attacker can deliver the malicious DLL via a remote vector (e.g., network share, Stuxnet-style propagation) before local execution occurs. ↗
- ·Malware and public exploits are known to exist for this vulnerability, raising the operational risk for unpatched STEP 7 deployments. ↗
CVSS provenance
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
vulncheck6.9MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SIMATIC STEP 7 DLL Vulnerability
cisa_ics·2013-05-08
Siemens SIMATIC STEP 7 DLL Vulnerability
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SIMATIC STEP 7 DLL Vulnerability
Last RevisedMay 08, 2013
Alert CodeICSA-12-205-02
## Overview
Siemens has released a software update for a DLL hijacking vulnerability in SIMATIC STEP 7 and SIMATIC PCS 7 software. Previous versions of SIMATIC STEP 7 and PCS 7 allowed the loading of malicious DLL files into the STEP 7 project folder that can be used to attack the system on which STEP 7 is installed. This vulnerability can be remotely exploited, as was the case with Stuxnet malware which was known to target this vulnerability. Siemens has produced a patch that resolves thi
GHSA
GHSA-jvr3-fqr5-pf4c: Untrusted search path vulnerability in Siemens SIMATIC STEP7 before 5
ghsa_unreviewed·2022-05-17
CVE-2012-3015 [MEDIUM] GHSA-jvr3-fqr5-pf4c: Untrusted search path vulnerability in Siemens SIMATIC STEP7 before 5
Untrusted search path vulnerability in Siemens SIMATIC STEP7 before 5.5 SP1, as used in SIMATIC PCS7 7.1 SP3 and earlier and other products, allows local users to gain privileges via a Trojan horse DLL in a STEP7 project folder.
VulnCheck
Siemens simatic_pcs7 Untrusted Search Path
vulncheck·2012·CVSS 6.9
CVE-2012-3015 [MEDIUM] Siemens simatic_pcs7 Untrusted Search Path
Siemens simatic_pcs7 Untrusted Search Path
Untrusted search path vulnerability in Siemens SIMATIC STEP7 before 5.5 SP1, as used in SIMATIC PCS7 7.1 SP3 and earlier and other products, allows local users to gain privileges via a Trojan horse DLL in a STEP7 project folder.
Affected: Siemens simatic_pcs7
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://www.welivesecurity.com/wp-content/uploads/2021/12/eset_jumping_the_air_gap_wp.pdf; https://hub.dragos.com/hubfs/312-Year-in-Review/2025/Dragos-2025-OT-Cybersecurity-Report-A-Year-in-Review.pdf
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-110665.pdfhttp://www.us-cert.gov/control_systems/pdf/ICSA-12-205-02.pdfhttp://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-110665.pdfhttp://www.us-cert.gov/control_systems/pdf/ICSA-12-205-02.pdf
2012-07-26
Published
Exploited in the wild