Vulnerability Description
Many of the services used by the affected product do not specify full paths for the DLLs they are loading. An attacker can exploit the uncontrolled search path by implanting their own DLL near the affected product’s binaries, thus hijacking the loaded DLL.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Auvesy | Versiondog | < 8.0.0 |
Related Weaknesses (CWE)
References
- https://us-cert.cisa.gov/ics/advisories/icsa-21-292-01PatchThird Party AdvisoryUS Government Resource
- https://us-cert.cisa.gov/ics/advisories/icsa-21-292-01PatchThird Party AdvisoryUS Government Resource
FAQ
What is CVE-2021-38469?
CVE-2021-38469 is a vulnerability with a CVSS score of 9.1 (CRITICAL). Many of the services used by the affected product do not specify full paths for the DLLs they are loading. An attacker can exploit the uncontrolled search path by implanting their own DLL near the aff...
How severe is CVE-2021-38469?
CVE-2021-38469 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-38469?
Check the references section above for vendor advisories and patch information. Affected products include: Auvesy Versiondog.