Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-24h9-pvx3-c6g5

Опубликовано: 18 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.5
CVSS3: 7.8

Описание

Hubstaff 1.6.14 contains a DLL search order hijacking vulnerability that allows attackers to replace a missing system32 wow64log.dll with a malicious library. Attackers can generate a custom DLL using Metasploit and place it in the system32 directory to obtain a reverse shell during application startup.

Hubstaff 1.6.14 contains a DLL search order hijacking vulnerability that allows attackers to replace a missing system32 wow64log.dll with a malicious library. Attackers can generate a custom DLL using Metasploit and place it in the system32 directory to obtain a reverse shell during application startup.

EPSS

Процентиль: 2%
0.00015
Низкий

8.5 High

CVSS4

7.8 High

CVSS3

Дефекты

CWE-427

Связанные уязвимости

CVSS3: 7.8
nvd
около 2 месяцев назад

Hubstaff 1.6.14 contains a DLL search order hijacking vulnerability that allows attackers to replace a missing system32 wow64log.dll with a malicious library. Attackers can generate a custom DLL using Metasploit and place it in the system32 directory to obtain a reverse shell during application startup.

EPSS

Процентиль: 2%
0.00015
Низкий

8.5 High

CVSS4

7.8 High

CVSS3

Дефекты

CWE-427