CVE-2024-6473: DLL Hijacking in Yandex Browser
Published Sep 3, 2024
·Updated
Yandex Browser for Desktop before 24.7.1.380 has a DLL Hijacking Vulnerability because an untrusted search path is used.
Affected Software
1 affected component
Yandex Yandex Browser<24.7.1.380
Event History
Sep 3, 2024
CVE Published
via MITRE·10:35 AM
Data Sourced
via MITRE·10:35 AM
DescriptionWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-6473?
CVE-2024-6473 is classified as a medium severity DLL hijacking vulnerability.
2
How do I fix CVE-2024-6473?
To fix CVE-2024-6473, update Yandex Browser to version 24.7.1.380 or later.
3
What causes CVE-2024-6473?
CVE-2024-6473 is caused by an untrusted search path that allows DLL hijacking in Yandex Browser.
4
Which versions of Yandex Browser are affected by CVE-2024-6473?
Yandex Browser versions prior to 24.7.1.380 are affected by CVE-2024-6473.
5
Is CVE-2024-6473 exploitable remotely?
Yes, CVE-2024-6473 can be exploited remotely by attackers through malicious DLL files.