CVE-2016-1417: High severity Snort Snort Windows vulnerability
Published Jan 23, 2017
·Updated
Untrusted search path vulnerability in Snort 2.9.7.0-WIN32 allows remote attackers to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse tcapi.dll that is located in the same folder on a remote file share as a pcap file that is being processed.
Affected Software
1 affected component
Snort Snort Windows=2.9.7.0
Event History
Jan 23, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Data Sourced
via NVD·09:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-1417?
CVE-2016-1417 has a high severity rating due to the potential for remote code execution and DLL hijacking.
2
How do I fix CVE-2016-1417?
To fix CVE-2016-1417, ensure that Snort is updated to a version that mitigates this vulnerability.
3
What is affected by CVE-2016-1417?
CVE-2016-1417 affects Snort version 2.9.7.0 on Windows systems.
4
What type of attack is associated with CVE-2016-1417?
CVE-2016-1417 is associated with DLL hijacking attacks that could allow execution of arbitrary code.
5
Can CVE-2016-1417 be exploited without user interaction?
Yes, CVE-2016-1417 can be exploited remotely without requiring user interaction.