F5-K76964818: High severity f5 big-ip access policy manager vulnerability
Published Feb 1, 2023
·Updated
A DLL hijacking vulnerability exists in the BIG-IP Edge Client Windows Installer.
Affected Software
6 affected componentsFixes available
f5 BIG-IP (APM)=17.0.0
17.1.0
f5 BIG-IP (APM)>=16.1.0<=16.1.3, =3
16.1.3.4
f5 BIG-IP (APM)>=15.1.0<=15.1.8, =3
15.1.8.2
f5 BIG-IP (APM)>=14.1.0<=14.1.5, =3
f5 BIG-IP (APM)>=13.1.0<=13.1.5, =3
f5 BIG-IP APM Clients>=7.2.2<=7.2.3
7.2.4
Event History
Feb 1, 2023
Advisory Published
via F5·01:02 PM
Frequently Asked Questions
1
What is the severity of F5-K76964818?
The severity of F5-K76964818 is classified as critical due to the potential for remote code execution.
2
How do I fix F5-K76964818?
To fix F5-K76964818, upgrade to the recommended patched versions of BIG-IP Edge Client or BIG-IP APM Clients.
3
What products are affected by F5-K76964818?
F5-K76964818 affects various versions of F5 BIG-IP (APM) and BIG-IP APM Clients.
4
What is a DLL hijacking vulnerability in F5-K76964818?
A DLL hijacking vulnerability in F5-K76964818 allows an attacker to execute arbitrary code by exploiting the loading mechanism of shared libraries.
5
Is there a workaround for F5-K76964818?
There is no official workaround for F5-K76964818; updating to the fixed releases is recommended.