Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-38469

Опубликовано: 22 окт. 2021
Источник: nvd
CVSS3: 9.1
CVSS3: 7.1
CVSS2: 4.3
EPSS Низкий

Описание

Many of the services used by the affected product do not specify full paths for the DLLs they are loading. An attacker can exploit the uncontrolled search path by implanting their own DLL near the affected product’s binaries, thus hijacking the loaded DLL.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:auvesy:versiondog:*:*:*:*:*:*:*:*
Версия до 8.0.0 (исключая)

EPSS

Процентиль: 33%
0.00128
Низкий

9.1 Critical

CVSS3

7.1 High

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-427

Связанные уязвимости

github
больше 3 лет назад

Many of the services used by the affected product do not specify full paths for the DLLs they are loading. An attacker can exploit the uncontrolled search path by implanting their own DLL near the affected product’s binaries, thus hijacking the loaded DLL.

EPSS

Процентиль: 33%
0.00128
Низкий

9.1 Critical

CVSS3

7.1 High

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-427