DLL Pre-Loading Vulnerability in Symantec VIP Access for Desktop
CVE-2017-6329
7.8HIGH
What is CVE-2017-6329?
Symantec VIP Access for Desktop versions before 2.2.4 are vulnerable to a DLL Pre-Loading flaw. This vulnerability occurs when the application attempts to load a dynamic link library (DLL) during execution. If an attacker can place a malicious DLL in the application's search path, the application may inadvertently load and execute this untrusted DLL, allowing potential execution of harmful code with the application's permissions. This can lead to unauthorized actions or data leakage under the context of the application.
Affected Version(s)
VIP Access for Desktop prior to 2.2.4