Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-46330

Опубликовано: 21 дек. 2022
Источник: nvd
CVSS3: 7.8
EPSS Низкий

Описание

Squirrel.Windows is both a toolset and a library that provides installation and update functionality for Windows desktop applications. Installers generated by Squirrel.Windows 2.0.1 and earlier contain an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries. As a result, arbitrary code may be executed with the privilege of the user invoking the installer.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:squirrel.windows_project:squirrel.windows:*:*:*:*:*:*:*:*
Версия до 2.0.1 (включая)

EPSS

Процентиль: 45%
0.0023
Низкий

7.8 High

CVSS3

Дефекты

CWE-427
CWE-427

Связанные уязвимости

CVSS3: 7.8
github
около 3 лет назад

Squirrel.Windows is both a toolset and a library that provides installation and update functionality for Windows desktop applications. Installers generated by Squirrel.Windows 2.0.1 and earlier contain an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries. As a result, arbitrary code may be executed with the privilege of the user invoking the installer.

EPSS

Процентиль: 45%
0.0023
Низкий

7.8 High

CVSS3

Дефекты

CWE-427
CWE-427