CVE-2021-38469
Summary
| CVE | CVE-2021-38469 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-10-22 12:15:00 UTC |
| Updated | 2021-10-28 18:52:00 UTC |
| Description | Many of the services used by the affected product do not specify full paths for the DLLs they are loading. An attacker can exploit the uncontrolled search path by implanting their own DLL near the affected product’s binaries, thus hijacking the loaded DLL. |
Risk And Classification
Problem Types: CWE-427
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Auvesy | Versiondog | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| AUVESY Versiondog | CISA | CONFIRM | us-cert.cisa.gov | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Amir Preminger of Claroty reported these vulnerabilities to CISA.
Legacy QID Mappings
- 590588 AUVESY Versiondog Multiple Vulnerabilities (ICSA-21-292-01)