DLL Hijacking Vulnerability in Akamai NetSession from Akamai Technologies
CVE-2016-10157

9.8CRITICAL

Key Information:

Vendor

Akamai

Vendor
CVE Published:
23 January 2017

What is CVE-2016-10157?

A critical vulnerability exists in Akamai NetSession version 1.9.3.1 due to improper handling of DLL loading. The application attempts to load the CSUNSAPI.dll without specifying a complete path, which can lead to DLL Hijacking. The absence of the legitimate DLL file in the installation increases the risk, allowing an attacker to exploit this flaw. By hijacking the DLL, an attacker can inject malicious code into the Akamai NetSession's process space, potentially compromising system integrity and security.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2016-10157 : DLL Hijacking Vulnerability in Akamai NetSession from Akamai Technologies