DLL Search Path Inequality in Squirrel.Windows by Squirrel
CVE-2022-46330

7.8HIGH

Key Information:

Vendor

Squirrel

Vendor
CVE Published:
21 December 2022

What is CVE-2022-46330?

Squirrel.Windows, a library and toolset for installing and updating Windows desktop applications, has a vulnerability in versions 2.0.1 and earlier due to an improper DLL search path configuration. This flaw allows for the insecure loading of Dynamic Link Libraries (DLLs), which may lead to the execution of arbitrary code with the privileges of the user running the installer. This presents a risk of exploitation by attackers to gain unauthorized access or manipulate the system functionalities. It's crucial for users to update to the latest version to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Installers generated by Squirrel.Windows 2.0.1 and earlier

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.