DLL Search Path Inequality in Squirrel.Windows by Squirrel
CVE-2022-46330
7.8HIGH
What is CVE-2022-46330?
Squirrel.Windows, a library and toolset for installing and updating Windows desktop applications, has a vulnerability in versions 2.0.1 and earlier due to an improper DLL search path configuration. This flaw allows for the insecure loading of Dynamic Link Libraries (DLLs), which may lead to the execution of arbitrary code with the privileges of the user running the installer. This presents a risk of exploitation by attackers to gain unauthorized access or manipulate the system functionalities. It's crucial for users to update to the latest version to mitigate this risk.
Affected Version(s)
Installers generated by Squirrel.Windows 2.0.1 and earlier
