Loading
Generated remediation guidance and an executive summary. No account required.
The writeRandomBytes_RtlGenRandom function in xmlparse.c in libexpat in Expat 2.2.1 and 2.2.2 on Windows allows local users to gain privileges via a Trojan horse ADVAPI32.DLL in the current working directory because of an untrusted search path, aka DLL hijacking.
Cite this page
CVE-2017-11742. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2017-11742
Use CWE-426, Libexpat Project vendor hub and Libexpat product page to widen CVE-2017-11742 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2024-45492, CVE-2024-45491 and CVE-2025-59375 for nearby disclosures in the same product family.