CVE-2024-57426

NetMod VPN Client 5.3.1 is vulnerable to DLL injection, allowing an attacker to execute arbitrary code by placing a malicious DLL in a directory where the application loads dependencies. This vulnerability arises due to the improper validation of dynamically loaded libraries.
Configurations

No configuration.

History

11 Feb 2025, 22:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.3
CWE CWE-427
Summary
  • (es) NetMod VPN Client 5.3.1 es vulnerable a la inyección de DLL, lo que permite a un atacante ejecutar código arbitrario colocando una DLL maliciosa en un directorio donde la aplicación carga dependencias. Esta vulnerabilidad surge debido a la validación incorrecta de librerías cargadas dinámicamente.

06 Feb 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-06 20:15

Updated : 2025-02-11 22:15


NVD link : CVE-2024-57426

Mitre link : CVE-2024-57426

CVE.ORG link : CVE-2024-57426


JSON object : View

Products Affected

No product.

CWE
CWE-427

Uncontrolled Search Path Element