DLL Preloading Vulnerability in Rapid7 Metasploit Pro Installers
CVE-2017-5235
7.8HIGH
What is CVE-2017-5235?
Rapid7 Metasploit Pro installers prior to version 4.13.0-2017022101 are susceptible to a DLL preloading vulnerability. This flaw allows a malicious actor to place a harmful DLL within the current working directory of the installer, which can be loaded unintentionally during the installation process. As a result, this vulnerability presents an opportunity for unauthorized code execution, posing significant risks to systems utilizing affected versions. Users are strongly advised to upgrade to the latest version to mitigate potential exploitation.
Affected Version(s)
Metasploit Pro All versions prior to version 4.13.0-2017022101