AXIS IP Utility before 4.18.0 allows for remote code execution and local privilege escalation by the means of DLL hijacking. IPUtility.exe would attempt to load DLLs from its current working directory which could allow for remote code execution if a compromised DLL would be placed in the same folder.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-28487 | AXIS IP Utility before 4.18.0 allows for remote code execution and local privilege escalation by the means of DLL hijacking. IPUtility.exe would attempt to load DLLs from its current working directory which could allow for remote code execution if a compromised DLL would be placed in the same folder. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.axis.com/files/tech_notes/CVE-2022-23410.pdf |
|
History
No history.
Status: PUBLISHED
Assigner: Axis
Published:
Updated: 2024-11-08T08:21:37.447Z
Reserved: 2022-01-18T00:00:00
Link: CVE-2022-23410
No data.
Status : Modified
Published: 2022-02-14T22:15:08.147
Modified: 2024-11-21T06:48:31.713
Link: CVE-2022-23410
No data.
OpenCVE Enrichment
No data.
EUVD