QID 375645

Date Published: 2021-08-12

QID 375645: Cisco Packet Tracer for Windows DLL Injection Vulnerability(cisco-sa-packettracer-dll-inj-Qv8Mk5Jx)

A vulnerability in Cisco Packet Tracer for Windows could allow an authenticated,
local attacker to perform a DLL injection attack on an affected
device. To exploit this vulnerability, the attacker must have valid credentials on the Windows system.

Affected Products
32bit and 64bit Cisco Packet Tracer for Windows Releases 7.3.1 and 8.0.0

QID Detection Logic (authenticated):
This QID looks for the vulnerable version of Cisco Packet Tracer

A successful exploit could allow an attacker with normal user privileges to execute arbitrary code on the affected system with the privileges of another user account.

  • CVSS V3 rated as High - 7.3 severity.
  • CVSS V2 rated as High - 6.9 severity.
  • Solution

    Customers are advised to refer to cisco-sa-packettracer-dll-inj-Qv8Mk5Jx for more information.

    CVEs related to QID 375645

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-packettracer-dll-inj-Qv8Mk5Jx URL Logo tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-packettracer-dll-inj-Qv8Mk5Jx