CVE-2017-9961: Schneider Electric Pro-Face Gp Pro Ex

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

A vulnerability exists in Schneider Electric's Pro-Face GP Pro EX version 4.07.000 that allows an attacker to execute arbitrary code. Malicious code installation requires an access to the computer. By placing a specific DLL/OCX file, an attacker is able to force the process to load arbitrary DLL and execute arbitrary code in the context of the process.

Affected products

Published 2017-09-26. Last modified 2026-06-17.