CVE-2017-5236: High severity rapid7 appspider vulnerability
Editions of Rapid7 AppSpider Pro installers prior to version 6.14.060 contain a DLL preloading vulnerability, wherein it is possible for the installer to load a malicious DLL located in the current working directory of the installer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-5236?
CVE-2017-5236 is classified as a medium severity vulnerability due to its potential for exploitation via DLL preloading.
How do I fix CVE-2017-5236?
To fix CVE-2017-5236, upgrade your Rapid7 AppSpider Pro installation to version 6.14.060 or later.
What specific versions of Rapid7 AppSpider Pro are affected by CVE-2017-5236?
CVE-2017-5236 affects all versions of Rapid7 AppSpider Pro prior to version 6.14.060.
What type of attack does CVE-2017-5236 vulnerability enable?
CVE-2017-5236 enables attackers to exploit the installation process by loading a malicious DLL from the current working directory.
What is DLL preloading as related to CVE-2017-5236?
DLL preloading in the context of CVE-2017-5236 refers to the ability of the installer to load dynamic link libraries that may have been tampered with from improper directories.