DLL Preloading Vulnerability in Rapid7 Metasploit Pro Installers
CVE-2017-5235

7.8HIGH

Key Information:

Vendor

Rapid7

Vendor
CVE Published:
2 March 2017

What is CVE-2017-5235?

Rapid7 Metasploit Pro installers prior to version 4.13.0-2017022101 are susceptible to a DLL preloading vulnerability. This flaw allows a malicious actor to place a harmful DLL within the current working directory of the installer, which can be loaded unintentionally during the installation process. As a result, this vulnerability presents an opportunity for unauthorized code execution, posing significant risks to systems utilizing affected versions. Users are strongly advised to upgrade to the latest version to mitigate potential exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Metasploit Pro All versions prior to version 4.13.0-2017022101

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.