CVE-2021-38469
Last modified
CVE-2021-38469 is a high-severity vulnerability rated 7.1/10 on the CVSS scale. Many of the services used by the affected product do not specify full paths for the DLLs they are loading. An attacker can exploit the uncontrolled search path by implanting their own DLL near the affected product’s binaries, thus hijacking the loaded DLL.. EPSS estimates a 0.60% chance of exploitation in the next 30 days.
Description
Many of the services used by the affected product do not specify full paths for the DLLs they are loading. An attacker can exploit the uncontrolled search path by implanting their own DLL near the affected product’s binaries, thus hijacking the loaded DLL.
Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Auvesy | Versiondog | < 8.0.0 |
References
- https://us-cert.cisa.gov/ics/advisories/icsa-21-292-01Patch, Third Party Advisory, US Government Resource
- https://us-cert.cisa.gov/ics/advisories/icsa-21-292-01Patch, Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-38469?
How severe is CVE-2021-38469?
How do I fix CVE-2021-38469?
Are you affected by CVE-2021-38469?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
