QID 378091
Date Published: 2023-03-22
QID 378091: F5 BIG-IP Access Policy Manager (APM) Edge Client for Windows Vulnerability CVE-2023-22358 (K76964818)
A DLL hijacking vulnerability exists in the BIG-IP Edge Client Windows Installer, DLL Hijacking is an attack vector that could allow attackers to exploit Windows applications search and load Dynamic Link Libraries (DLL). If a web app is vulnerable to DLL Hijacking, attackers can load malicious DLLs in the PATH or other location that is searched by the application and have them executed by the application. (CVE-2023-22358)
Vulnerable Component: BIG-IP APM
Affected Versions:
17.0.0
16.1.0 - 16.1.3
15.1.0 - 15.1.8
14.1.0 - 14.1.5
13.1.0 - 13.1.5
QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of F5 BIG-IP devices using the tmsh command.
An attacker may exploit this vulnerability to use malicious Dynamic Link Libraries (DLL) to gain privilege escalation on the client Windows system. The installer loads the DLL and runs the malicious code that could grant administrative privileges to the attacker.
- K76964818 -
my.f5.com/manage/s/article/K76964818
CVEs related to QID 378091
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| K76964818 |
|