CVE-2017-5235: High severity Rapid7 Metasploit vulnerability
Rapid7 Metasploit Pro installers prior to version 4.13.0-2017022101 contain a DLL preloading vulnerability, wherein it is possible for the installer to load a malicious DLL located in the current working directory of the installer.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Rapid7 Metasploit Proto a version that resolves this vulnerability.Fixed in 4.13.0-2017022101 - Compensating control
Ensure the installer is executed from a directory that does not contain attacker-controlled DLLs in the current working directory to prevent malicious DLL preloading during installation.
Event History
Frequently Asked Questions
What is the severity of CVE-2017-5235?
The severity of CVE-2017-5235 is classified as medium due to the potential for unauthorized code execution.
How do I fix CVE-2017-5235?
To fix CVE-2017-5235, upgrade to Rapid7 Metasploit Pro version 4.13.0-2017022101 or later.
What impact does CVE-2017-5235 have on my system?
CVE-2017-5235 can allow an attacker to execute malicious code by exploiting the DLL preloading vulnerability during installation.
What version of Metasploit is affected by CVE-2017-5235?
Versions of Rapid7 Metasploit Pro prior to 4.13.0-2017022101 are affected by CVE-2017-5235.
Is CVE-2017-5235 a local or remote vulnerability?
CVE-2017-5235 is considered a local vulnerability, as it requires local access to the system to exploit.