DLL Search Path Inequality in Squirrel.Windows by Squirrel
CVE-2022-46330

7.8HIGH

Key Information:

Vendor

Squirrel

Vendor
CVE Published:
21 December 2022

What is CVE-2022-46330?

Squirrel.Windows, a library and toolset for installing and updating Windows desktop applications, has a vulnerability in versions 2.0.1 and earlier due to an improper DLL search path configuration. This flaw allows for the insecure loading of Dynamic Link Libraries (DLLs), which may lead to the execution of arbitrary code with the privileges of the user running the installer. This presents a risk of exploitation by attackers to gain unauthorized access or manipulate the system functionalities. It's crucial for users to update to the latest version to mitigate this risk.

Affected Version(s)

Installers generated by Squirrel.Windows 2.0.1 and earlier

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.