CVE-2024-9497
Severity CVSS v4.0:
Pending analysis
Type:
CWE-427
Uncontrolled Search Path Element
Publication date:
24/01/2025
Last modified:
24/01/2025
Description
DLL hijacking vulnerabilities, caused by an uncontrolled search path in the USBXpress 4 SDK<br />
<br />
<br />
<br />
<br />
<br />
installer can lead to privilege escalation and arbitrary code execution when running the impacted installer.
Impact
Base Score 3.x
8.60
Severity 3.x
HIGH