Executive brief
HCL Traveler for Microsoft Outlook (HTMO), a tool that allows users to access HCL Domino mail and calendar data within the Outlook client, is vulnerable to a security flaw. An attacker with high-level access to a user's computer could replace legitimate application files with malicious ones. If successful, this could allow the attacker to take full control of the application, potentially leading to the theft of sensitive email data or further compromise of the local system.
Technical details
HCL Traveler for Microsoft Outlook (HTMO) is vulnerable to DLL hijacking (CWE-427: Uncontrolled Search Path Element). The application fails to properly validate or restrict the search path used to load dynamic link libraries (DLLs), allowing an attacker to place a malicious DLL in a location where it will be loaded by the application. Exploitation requires local access and high privileges (PR:H) on the target machine, as well as user interaction (UI:R). Successful exploitation allows for arbitrary code execution with the privileges of the HTMO process, potentially compromising confidentiality, integrity, and availability. The vulnerability is addressed in HTMO version 3.0.16.
Affected products
- HCL Software Traveler for Microsoft Outlook (HTMO) < 3.0.16
Timeline
- 2026-07-17: disclosed
- 2026-07-17: advisory