CVE-2024-45873

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Oct 7, 2024
Updated: Oct 10, 2024
CWE ID 94

Summary

CVE-2024-45873 is a newly discovered DLL hijacking vulnerability affecting VegaBird Yaazhini 2.0.2. This issue permits attackers to execute arbitrary code or establish persistence by strategically placing a malicious DLL file in the same directory as Yaazhini.exe. The attacker takes advantage of the application's failure to properly check for the authenticity of the DLL file, potentially leading to serious security implications.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share