First published: Fri Jan 05 2024(Updated: )
There is a DLL hijacking vulnerability in ZTE ZXCLOUD iRAI, an attacker could place a fake DLL file in a specific directory and successfully exploit this vulnerability to execute malicious code.
Credit: psirt@zte.com.cn
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ZTE ZXCloud iRAI | <7.23.30 | |
ZTE ZXCloud iRAI |
V7.23.30
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-41782 is considered a high-severity vulnerability due to its potential to allow remote code execution.
To fix CVE-2023-41782, update ZTE ZXCLOUD iRAI to version 7.23.30 or later.
A DLL hijacking vulnerability, like CVE-2023-41782, occurs when an attacker can place a malicious DLL file in a directory where a legitimate application could load it.
CVE-2023-41782 affects versions of ZTE ZXCLOUD iRAI prior to 7.23.30.
By exploiting CVE-2023-41782, attackers can execute arbitrary code on the affected system, potentially leading to a complete system compromise.