First published: Thu Mar 02 2017(Updated: )
Rapid7 AppSpider Pro installers prior to version 6.14.053 contain a DLL preloading vulnerability, wherein it is possible for the installer to load a malicious DLL located in the current working directory of the installer.
Credit: cve@rapid7.con
Affected Software | Affected Version | How to fix |
---|---|---|
Rapid7 AppSpider | <6.14.053 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-5233 is classified as a medium severity vulnerability due to the potential for exploitation through DLL preloading.
To fix CVE-2017-5233, upgrade to Rapid7 AppSpider Pro version 6.14.053 or later.
CVE-2017-5233 is a DLL preloading vulnerability that allows loading of malicious DLLs.
The vulnerability affects all versions of Rapid7 AppSpider Pro prior to version 6.14.053.
CVE-2017-5233 requires local access to the machine running the installer, thereby limiting remote exploitation.