← Back

CVE-2022-23410

nvd nist
Published: Feb 14, 2022Modified: Nov 21, 2024

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

AXIS IP Utility before 4.18.0 allows for remote code execution and local privilege escalation by the means of DLL hijacking. IPUtility.exe would attempt to load DLLs from its current working directory which could allow for remote code execution if a compromised DLL would be placed in the same folder.

Affected (1)

Products: Axis: Ip Utility
1 product
Ip Utility
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 4.18.0

References (2)

Source: product-security@axis.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.