CVE-2024-12168

Yandex Telemost for Desktop before 2.7.0 has a DLL Hijacking Vulnerability because an untrusted search path is used.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:yandex:yandex_telemost:2.7.0:*:*:*:*:-:*:*

History

03 Dec 2025, 21:16

Type Values Removed Values Added
Summary
  • (es) Yandex Telemost para Desktop anterior a 2.7.0 tiene una vulnerabilidad de secuestro de DLL porque se utiliza una ruta de búsqueda no confiable.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
First Time Yandex yandex Telemost
Yandex
CPE cpe:2.3:a:yandex:yandex_telemost:2.7.0:*:*:*:*:-:*:*
References () https://yandex.com/bugbounty/i/hall-of-fame-products - () https://yandex.com/bugbounty/i/hall-of-fame-products - Vendor Advisory

02 Jun 2025, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-02 13:15

Updated : 2025-12-03 21:16


NVD link : CVE-2024-12168

Mitre link : CVE-2024-12168

CVE.ORG link : CVE-2024-12168


JSON object : View

Products Affected

yandex

  • yandex_telemost
CWE
CWE-426

Untrusted Search Path