HomeWesterndigitalCVE-2023-22818

CVE-2023-22818

HIGH
7.3CVSS
Published: 2023-11-15
Updated: 2024-11-21
AI Analysis

Description

Multiple DLL Search Order Hijack vulnerabilities were addressed in the SanDisk Security Installer for Windows that could allow attackers with local access to execute arbitrary code by executing the installer in the same folder as the malicious DLL. This can lead to the execution of arbitrary code with the privileges of the vulnerable application or obtain a certain level of persistence on the compromised host. 

CVSS Metrics

Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Attack Vector
local
Complexity
low
Privileges
low
User Action
required
Scope
unchanged
Confidentiality
high
Integrity
high
Availability
high
Weaknesses
CWE-427CWE-427

Metadata

Primary Vendor
WESTERNDIGITAL
Published
11/15/2023
Last Modified
11/21/2024
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

westerndigital : sandisk_security_installer

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2023-22818 | HIGH Severity | CVEDatabase.com | CVEDatabase.com