DLL Preloading Vulnerability in Rapid7 Metasploit Pro Installers
CVE-2017-5235

7.8HIGH

Key Information:

Vendor

Rapid7

Vendor
CVE Published:
2 March 2017

What is CVE-2017-5235?

Rapid7 Metasploit Pro installers prior to version 4.13.0-2017022101 are susceptible to a DLL preloading vulnerability. This flaw allows a malicious actor to place a harmful DLL within the current working directory of the installer, which can be loaded unintentionally during the installation process. As a result, this vulnerability presents an opportunity for unauthorized code execution, posing significant risks to systems utilizing affected versions. Users are strongly advised to upgrade to the latest version to mitigate potential exploitation.

Affected Version(s)

Metasploit Pro All versions prior to version 4.13.0-2017022101

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.