← Vulnerability feed

Vulnerability record · CVE-2024-42190 · published 30 May 2025

CVE-2024-42190: Hcltech traveler for microsoft outlook uncontrolled search path element vulnerability

Hcltech · Traveler For Microsoft Outlook

HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a DLL hijacking vulnerability which could allow an attacker to modify or replace the application with malicious content.

9.8 CVSS 3.1 Critical EPSS 0.27% · top 82.8% CWE-427 · Uncontrolled search path element
9.8CVSS 3.1 base score
0.27%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a DLL hijacking vulnerability which could allow an attacker to modify or replace the application with malicious content.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-42190 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-42191Hcltech traveler for microsoft outlook uncontrolled search path element vulnerabilityHCL Traveler for Microsoft Outlook (HTMO) is susceptible to a COM hijacking vulnerability which could allow an attacker to modify or replace the appl…EPSS 0.27%7.8CVE-2023-37524Hcltech traveler for microsoft outlook vulnerabilityHCL Traveler for Microsoft Outlook (HTMO) is susceptible to vulnerabilities due to .NET Framework 4.5 being out of service.  Since .NET Framework 4.5…EPSS 0.27%7.8CVE-2024-23581Hcltech traveler for microsoft outlook improper verification of cryptographic signature vulnerabilityThe HCL Traveler for Microsoft Outlook libraries are being flagged as potentially malicious software or an unrecognized application.EPSS 0.09%7.5CVE-2024-30134Hcltech traveler for microsoft outlook improper certificate validation vulnerabilityThe HCL Traveler for Microsoft Outlook executable (HTMO.exe) is being flagged as potentially Malicious Software or an Unrecognized Application.EPSS 0.21%5.5CVE-2025-59868Hcltech traveler for microsoft outlook sensitive information in log file vulnerabilityHCL Traveler for Microsoft Outlook (HTMO) is susceptible to a sensitive data exposure vulnerability which could allow an attacker to exploit applicat…EPSS 0.15%5.5CVE-2024-42192Hcltech traveler for microsoft outlook insufficiently protected credentials vulnerabilityHCL Traveler for Microsoft Outlook (HTMO) is susceptible to a credential leakage which could allow an attacker to access other computers or applicati…EPSS 0.16%5.3CVE-2024-30133Hcltech traveler for microsoft outlook vulnerabilityHCL Traveler for Microsoft Outlook (HTMO) is susceptible to a control flow vulnerability. The application does not sufficiently manage its control fl…EPSS 0.26%7.8CVE-2020-3433Cisco AnyConnect Windows client DLL hijacking via IPC channelCisco AnyConnect Secure Mobility Client for Windows fails to properly validate resources loaded at run time, allowing a DLL hijacking attack through …KEVEPSS 10%analysed

Source: NIST National Vulnerability Database (record CVE-2024-42190), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.