CVE-2024-45873
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Oct 7, 2024
Updated: Oct 10, 2024
CWE ID 94
Summary
CVE-2024-45873 is a newly discovered DLL hijacking vulnerability affecting VegaBird Yaazhini 2.0.2. This issue permits attackers to execute arbitrary code or establish persistence by strategically placing a malicious DLL file in the same directory as Yaazhini.exe. The attacker takes advantage of the application's failure to properly check for the authenticity of the DLL file, potentially leading to serious security implications.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.