Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9x6g-6cj7-h5vc

Опубликовано: 15 нояб. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.3

Описание

Multiple DLL Search Order Hijack vulnerabilities were addressed in the SanDisk Security Installer for Windows that could allow attackers with local access to execute arbitrary code by executing the installer in the same folder as the malicious DLL. This can lead to the execution of arbitrary code with the privileges of the vulnerable application or obtain a certain level of persistence on the compromised host. 

Multiple DLL Search Order Hijack vulnerabilities were addressed in the SanDisk Security Installer for Windows that could allow attackers with local access to execute arbitrary code by executing the installer in the same folder as the malicious DLL. This can lead to the execution of arbitrary code with the privileges of the vulnerable application or obtain a certain level of persistence on the compromised host. 

EPSS

Процентиль: 5%
0.00021
Низкий

7.3 High

CVSS3

Дефекты

CWE-427

Связанные уязвимости

CVSS3: 7.3
nvd
около 2 лет назад

Multiple DLL Search Order Hijack vulnerabilities were addressed in the SanDisk Security Installer for Windows that could allow attackers with local access to execute arbitrary code by executing the installer in the same folder as the malicious DLL. This can lead to the execution of arbitrary code with the privileges of the vulnerable application or obtain a certain level of persistence on the compromised host. 

CVSS3: 7.3
fstec
около 2 лет назад

Уязвимость установщика программного средства защиты данных на USB-накопителях SanDisk SecureAccess, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 5%
0.00021
Низкий

7.3 High

CVSS3

Дефекты

CWE-427