Multiple DLL Search Order Hijack vulnerabilities were addressed in the SanDisk Security Installer for
Windows that could allow attackers with local access to execute arbitrary code by executing the installer
in the same folder as the malicious DLL. This can lead to the execution of arbitrary
code with the privileges of the vulnerable application or obtain a certain level of persistence
on the compromised host.
References
Link | Resource |
---|---|
https://vuldb.com/?id.245601 | Third Party Advisory |
https://www.westerndigital.com/support/product-security/wdc-23013-sandisk-security-installer-for-windows-1-0-0-25 | Broken Link |
Configurations
History
22 Nov 2023, 22:40
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-11-15 20:15
Updated : 2024-02-05 00:22
NVD link : CVE-2023-22818
Mitre link : CVE-2023-22818
CVE.ORG link : CVE-2023-22818
JSON object : View
Products Affected
westerndigital
- sandisk_security_installer
CWE
CWE-427
Uncontrolled Search Path Element