DLL Preloading Vulnerability in Cisco FindIT Network Discovery Utility
CVE-2017-12252
7.8HIGH
Summary
A vulnerability in the Cisco FindIT Network Discovery Utility allows an authenticated, local attacker to execute a DLL preloading attack. This can lead to a compromised system where the application inadvertently loads a malicious DLL file, instead of the expected file. If successfully exploited, the attacker could endanger the device’s confidentiality, integrity, and availability. This situation arises when an affected DLL is strategically placed within the host system's search path, creating potential risks for sensitive data and overall device functionality.
Affected Version(s)
Cisco FindIT Cisco FindIT
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved