CVE-2023-29444
Description
An uncontrolled search path element vulnerability (DLL hijacking) has been discovered that could allow a locally authenticated adversary to escalate privileges to SYSTEM. Alternatively, they could host a trojanized version of the software and trick victims into downloading and installing their malicious version to gain initial access and code execution.
- CVSS Version 3.1
nvd
CVE ID: CVE-2023-29444
Base Score: 7.3
Base Severity: HIGH
Vector String:CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Impact Score: 5.9
Exploitability Score: 1.3
dragos
CVE ID: CVE-2023-29444
Base Score: 6.3
Base Severity: MEDIUM
Vector String:CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H
Impact Score: 5.9
Exploitability Score: 0.3