Description
Multiple DLL Search Order Hijack vulnerabilities were addressed in the SanDisk Security Installer for
Windows that could allow attackers with local access to execute arbitrary code by executing the installer
in the same folder as the malicious DLL. This can lead to the execution of arbitrary
code with the privileges of the vulnerable application or obtain a certain level of persistence
on the compromised host.
Windows that could allow attackers with local access to execute arbitrary code by executing the installer
in the same folder as the malicious DLL. This can lead to the execution of arbitrary
code with the privileges of the vulnerable application or obtain a certain level of persistence
on the compromised host.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-26930 | Multiple DLL Search Order Hijack vulnerabilities were addressed in the SanDisk Security Installer for Windows that could allow attackers with local access to execute arbitrary code by executing the installer in the same folder as the malicious DLL. This can lead to the execution of arbitrary code with the privileges of the vulnerable application or obtain a certain level of persistence on the compromised host. |
References
History
No history.
Status: PUBLISHED
Assigner: WDC PSIRT
Published:
Updated: 2024-08-29T17:35:18.339Z
Reserved: 2023-01-06T20:23:44.301Z
Link: CVE-2023-22818
Updated: 2024-08-02T10:20:30.831Z
Status : Modified
Published: 2023-11-15T20:15:07.157
Modified: 2024-11-21T07:45:28.767
Link: CVE-2023-22818
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD