Hex-Rays IDA Pro 9.2 and 9.3 before 9.3sp2 does not block Clang dependency-file generation (via argument injection), which allows attackers to place their code into a plugins directory if the victim uses an attacker-supplied .i64 file.Referenceshttps://blog.calif.io/p/using-ida-to-find-bugs-in-ida-withhttps://docs.hex-rays.com/release-notes/9_3sp2