HIGH KEV
mDNSResponder.exe is vulnerable to DLL Sideloading attack
Published Nov 17, 2022 ·Due Feb 27, 2025
7.8
HIGHCVSS 3.1
EPSS 9.09%
Description
mDNSResponder.exe is vulnerable to DLL Sideloading attack. Executable improperly specifies how to load the DLL, from which folder and under what conditions. In these scenarios, a malicious attacker could be using the valid and legitimate executable to load malicious files.
Affected products
- Vendor n/a Product Audinate Dante Application Library for Windows Defaultn/a
- Version All versions prior to and including 1.2.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Audinate Dante Application Library for Windows | n/a |
|
AND
- ≤ 1.2.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (4)
- https://cpr-zero.checkpoint.com/vulns/cprid-2193/%2C Broken Link
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-28684 Advisory
- https://www.audinate.com/learning/faqs/audinate-response-to-dante-discovery-mdnsresponder-exe-security-issue-cve-2022-23748 Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-23748 government-resourceUS Government Resource
| Link | Providers | Tags |
|---|---|---|
| https://cpr-zero.checkpoint.com/vulns/cprid-2193/%2C | Broken Link | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-28684 | Advisory | |
| https://www.audinate.com/learning/faqs/audinate-response-to-dante-discovery-mdnsresponder-exe-security-issue-cve-2022-23748 | Vendor Advisory | |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-23748 | government-resourceUS Government Resource |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner checkpoint
Published Nov 17, 2022
Updated Oct 21, 2025
Reserved Jan 19, 2022
Link CVE-2022-23748
CISA Vulnrichment
Updated Feb 6, 2025
ENISA EUVD
EUVD-2022-28684 Assigner checkpoint
Published Nov 17, 2022
Updated Oct 21, 2025
Exploited since Feb 6, 2025
Link EUVD-2022-28684