DLL Hijacking Vulnerability in Flash Programming Utility by Silicon Labs
CVE-2024-9492
8.6HIGH
Summary
The Flash Programming Utility installer is vulnerable to DLL hijacking due to an uncontrolled search path. This flaw can allow unauthorized users to execute arbitrary code with elevated privileges during the installation of the software, potentially leading to significant security risks. Users are advised to review the advisory from Silicon Labs for mitigation strategies.
Affected Version(s)
Flash Programming Utility Windows 0 <= 4.80
References
CVSS V3.1
Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Thanks to Sahil Shah and Shaurya for reporting this issue.