First published: Thu Mar 02 2017(Updated: )
Rapid7 Metasploit Pro installers prior to version 4.13.0-2017022101 contain a DLL preloading vulnerability, wherein it is possible for the installer to load a malicious DLL located in the current working directory of the installer.
Credit: cve@rapid7.con
Affected Software | Affected Version | How to fix |
---|---|---|
Metasploit Framework | <=4.13.0-2017012501 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-5235 is classified as medium due to the potential for unauthorized code execution.
To fix CVE-2017-5235, upgrade to Rapid7 Metasploit Pro version 4.13.0-2017022101 or later.
CVE-2017-5235 can allow an attacker to execute malicious code by exploiting the DLL preloading vulnerability during installation.
Versions of Rapid7 Metasploit Pro prior to 4.13.0-2017022101 are affected by CVE-2017-5235.
CVE-2017-5235 is considered a local vulnerability, as it requires local access to the system to exploit.