CVE-2022-23748
גבוהה 7.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Dante Discovery Process Control Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
תיאור (מקור, אנגלית)
mDNSResponder.exe is vulnerable to DLL Sideloading attack. Executable improperly specifies how to load the DLL, from which folder and under what conditions. In these scenarios, a malicious attacker could be using the valid and legitimate executable to load malicious files.
מדדים
- CVSS 3.1
-
7.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 9% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-114, CWE-426
מוצרים מושפעים
audinate: dante application library; microsoft: windows
קישורים
- https://www.audinate.com/learning/faqs/audinate-response-to-dante-discovery-md… Vendor Advisory
- https://www.audinate.com/learning/faqs/audinate-response-to-dante-discovery-md… Vendor Advisory
- https://cpr-zero.checkpoint.com/vulns/cprid-2193/%2C Broken Link
- https://cpr-zero.checkpoint.com/vulns/cprid-2193/%2C Broken Link
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-202… US Government Resource