CVE-2024-9497: Uncontrolled search path can lead to DLL hijacking in USBXpress 4 SDK installer
DLL hijacking vulnerabilities, caused by an uncontrolled search path in the USBXpress 4 SDK
installer can lead to privilege escalation and arbitrary code execution when running the impacted installer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-9497?
CVE-2024-9497 has been rated as high severity due to its potential for privilege escalation and arbitrary code execution.
How do I fix CVE-2024-9497?
To fix CVE-2024-9497, ensure that you update the FTDI USBXpress 4 SDK to the latest version that resolves the DLL hijacking vulnerability.
What types of attacks can CVE-2024-9497 facilitate?
CVE-2024-9497 can facilitate attacks such as privilege escalation and arbitrary code execution via DLL hijacking when the affected installer is run.
Which software is affected by CVE-2024-9497?
CVE-2024-9497 specifically affects the FTDI USBXpress 4 SDK installer.
What is DLL hijacking in the context of CVE-2024-9497?
In the context of CVE-2024-9497, DLL hijacking refers to the exploitation of an uncontrolled search path that allows an attacker to execute malicious code through the USBXpress 4 SDK installer.