EXPOSURES › CVE-2022-23748
CVE-2022-23748
HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
⚡ RCE
⌖ EXPLOITED IN THE WILD
SHAME 65/100
rceexploited-in-wild
Audinate's Dante Discovery software contained a DLL sideloading vulnerability actively exploited in the wild, allowing local code execution.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
PLAYERS IMPLICATED
DESCRIPTION
Dante Discovery contains a process control vulnerability in mDNSResponder.exe that all allows for a DLL sideloading attack. A local attacker can leverage this vulnerability in the Dante Application Library to execute arbitrary code.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.