Untrusted Search Path Vulnerability in NetEase CloudMusic for Windows
CVE-2023-47454
7.8HIGH
What is CVE-2023-47454?
The vulnerability in NetEase CloudMusic 2.10.4 for Windows arises from the application improperly handling the search path of dynamic link libraries. This misconfiguration allows local users to escalate their privileges by exploiting the urlmon.dll file located in the current working directory. By manipulating this component, an attacker can execute arbitrary code with elevated rights, posing significant risks to user data and system integrity.
