CVE-2024-12168: DLL Hijacking in Yandex Telemost
Published Jun 2, 2025
·Updated
Yandex Telemost for Desktop before 2.7.0 has a DLL Hijacking Vulnerability because an untrusted search path is used.
Affected Software
2 affected components
Yandex Telemost<2.7.0
Yandex Yandex Telemost=2.7.0
Event History
Jun 2, 2025
CVE Published
via MITRE·12:44 PM
Data Sourced
via MITRE·12:44 PM
DescriptionWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-12168?
CVE-2024-12168 is considered a medium severity vulnerability due to its potential for DLL hijacking.
2
How do I fix CVE-2024-12168?
To fix CVE-2024-12168, upgrade Yandex Telemost to version 2.7.0 or later.
3
What software is affected by CVE-2024-12168?
CVE-2024-12168 affects Yandex Telemost for Desktop versions before 2.7.0.
4
What is the impact of CVE-2024-12168?
The impact of CVE-2024-12168 includes potential execution of arbitrary code through DLL hijacking.
5
Is there a workaround for CVE-2024-12168?
Currently, the recommended workaround for CVE-2024-12168 is to avoid using the vulnerable versions of Yandex Telemost until a fix is applied.