First published: Wed May 03 2017(Updated: )
Editions of Rapid7 AppSpider Pro installers prior to version 6.14.060 contain a DLL preloading vulnerability, wherein it is possible for the installer to load a malicious DLL located in the current working directory of the installer.
Credit: cve@rapid7.con
Affected Software | Affected Version | How to fix |
---|---|---|
Rapid7 AppSpider | <=6.14.059 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-5236 is classified as a medium severity vulnerability due to its potential for exploitation via DLL preloading.
To fix CVE-2017-5236, upgrade your Rapid7 AppSpider Pro installation to version 6.14.060 or later.
CVE-2017-5236 affects all versions of Rapid7 AppSpider Pro prior to version 6.14.060.
CVE-2017-5236 enables attackers to exploit the installation process by loading a malicious DLL from the current working directory.
DLL preloading in the context of CVE-2017-5236 refers to the ability of the installer to load dynamic link libraries that may have been tampered with from improper directories.