Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-69h8-2gjf-xq29

Опубликовано: 04 дек. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7

Описание

DLL injection in Veeam Agent for Windows can occur if the system's PATH variable includes insecure locations. When the agent runs, it searches these directories for necessary DLLs. If an attacker places a malicious DLL in one of these directories, the Veeam Agent might load it inadvertently, allowing the attacker to execute harmful code. This could lead to unauthorized access, data theft, or disruption of services

DLL injection in Veeam Agent for Windows can occur if the system's PATH variable includes insecure locations. When the agent runs, it searches these directories for necessary DLLs. If an attacker places a malicious DLL in one of these directories, the Veeam Agent might load it inadvertently, allowing the attacker to execute harmful code. This could lead to unauthorized access, data theft, or disruption of services

EPSS

Процентиль: 24%
0.00083
Низкий

7 High

CVSS3

Дефекты

CWE-426

Связанные уязвимости

CVSS3: 7
nvd
около 1 года назад

DLL injection in Veeam Agent for Windows can occur if the system's PATH variable includes insecure locations. When the agent runs, it searches these directories for necessary DLLs. If an attacker places a malicious DLL in one of these directories, the Veeam Agent might load it inadvertently, allowing the attacker to execute harmful code. This could lead to unauthorized access, data theft, or disruption of services

CVSS3: 7
fstec
больше 1 года назад

Уязвимость средства резервного копирования данных Veeam Agent for Microsoft Windows, связанная с использованием ненадёжного пути поиска, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 24%
0.00083
Низкий

7 High

CVSS3

Дефекты

CWE-426