CVE-2022-23410

Severity CVSS v4.0:
Pending analysis
Type:
CWE-427 Uncontrolled Search Path Element
Publication date:
14/02/2022
Last modified:
08/11/2024

Description

AXIS IP Utility before 4.18.0 allows for remote code execution and local privilege escalation by the means of DLL hijacking. IPUtility.exe would attempt to load DLLs from its current working directory which could allow for remote code execution if a compromised DLL would be placed in the same folder.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:axis:ip_utility:*:*:*:*:*:*:*:* 4.18.0 (excluding)


References to Advisories, Solutions, and Tools