Remote Code Execution Flaw in AXIS IP Utility by AXIS Communications
CVE-2022-23410

7.8HIGH

Key Information:

Vendor
CVE Published:
14 February 2022

What is CVE-2022-23410?

The AXIS IP Utility is susceptible to a serious security flaw due to improper handling of Dynamic Link Libraries (DLLs). Prior to version 4.18.0, the utility would load DLL files from its working directory, creating a risk where an attacker could exploit this behavior by placing a malicious DLL in the same folder. This could allow for remote code execution and result in local privilege escalation, potentially compromising the system's integrity and confidentiality. Users are advised to update to the latest version to mitigate these risks.

Affected Version(s)

AXIS IP Utility All version prior to 4.18.0

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.