DLL Hijacking Vulnerability in Flash Programming Utility by Silicon Labs
CVE-2024-9492

8.6HIGH

Key Information:

Vendor
Silabs.com
Status
Flash Programming Utility
Vendor
CVE Published:
24 January 2025

Summary

The Flash Programming Utility installer is vulnerable to DLL hijacking due to an uncontrolled search path. This flaw can allow unauthorized users to execute arbitrary code with elevated privileges during the installation of the software, potentially leading to significant security risks. Users are advised to review the advisory from Silicon Labs for mitigation strategies.

Affected Version(s)

Flash Programming Utility Windows 0 <= 4.80

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Thanks to Sahil Shah and Shaurya for reporting this issue.
.