Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-22818


Multiple DLL Search Order Hijack vulnerabilities were addressed in the SanDisk Security Installer for Windows that could allow attackers with local access to execute arbitrary code by executing the installer in the same folder as the malicious DLL. This can lead to the execution of arbitrary code with the privileges of the vulnerable application or obtain a certain level of persistence on the compromised host. 


Published

2023-11-15T20:15:07.157

Last Modified

2024-11-21T07:45:28.767

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.3 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-427
  • Type: Primary
    CWE-427

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application westerndigital sandisk_security_installer < 1.0.0.25 Yes

References