Squirrel.Windows is both a toolset and a library that provides installation and update functionality for Windows desktop applications. Installers generated by Squirrel.Windows 2.0.1 and earlier contain an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries. As a result, arbitrary code may be executed with the privilege of the user invoking the installer.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published: 2022-12-21T00:00:00

Updated: 2024-08-03T14:31:46.282Z

Reserved: 2022-12-14T00:00:00

Link: CVE-2022-46330

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-12-21T09:15:08.873

Modified: 2023-01-04T02:21:14.167

Link: CVE-2022-46330

cve-icon Redhat

No data.