DLL Preloading Vulnerability in Cisco FindIT Network Discovery Utility
CVE-2017-12252

7.8HIGH

Key Information:

Vendor
Cisco
Vendor
CVE Published:
21 September 2017

Summary

A vulnerability in the Cisco FindIT Network Discovery Utility allows an authenticated, local attacker to execute a DLL preloading attack. This can lead to a compromised system where the application inadvertently loads a malicious DLL file, instead of the expected file. If successfully exploited, the attacker could endanger the device’s confidentiality, integrity, and availability. This situation arises when an affected DLL is strategically placed within the host system's search path, creating potential risks for sensitive data and overall device functionality.

Affected Version(s)

Cisco FindIT Cisco FindIT

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.