Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4r89-vr67-8qj8

Опубликовано: 25 июл. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.5

Описание

A DLL injection vulnerability exists in Commvault for Windows 11.20.0, 11.28.0, 11.32.0, 11.34.0, and 11.36.0. During the installation of maintenance updates, an attacker with local access may exploit uncontrolled search path or DLL loading behavior to execute arbitrary code with elevated privileges. The vulnerability has been resolved in versions 11.20.202, 11.28.124, 11.32.65, 11.34.37, and 11.36.15.

A DLL injection vulnerability exists in Commvault for Windows 11.20.0, 11.28.0, 11.32.0, 11.34.0, and 11.36.0. During the installation of maintenance updates, an attacker with local access may exploit uncontrolled search path or DLL loading behavior to execute arbitrary code with elevated privileges. The vulnerability has been resolved in versions 11.20.202, 11.28.124, 11.32.65, 11.34.37, and 11.36.15.

EPSS

Процентиль: 4%
0.00018
Низкий

8.5 High

CVSS4

Дефекты

CWE-427

Связанные уязвимости

nvd
7 месяцев назад

A DLL injection vulnerability exists in Commvault for Windows 11.20.0, 11.28.0, 11.32.0, 11.34.0, and 11.36.0. During the installation of maintenance updates, an attacker with local access may exploit uncontrolled search path or DLL loading behavior to execute arbitrary code with elevated privileges. The vulnerability has been resolved in versions 11.20.202, 11.28.124, 11.32.65, 11.34.37, and 11.36.15.

EPSS

Процентиль: 4%
0.00018
Низкий

8.5 High

CVSS4

Дефекты

CWE-427