installer can lead to privilege escalation and arbitrary code execution when running the impacted installer.
Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-50353 | DLL hijacking vulnerabilities, caused by an uncontrolled search path in the USBXpress Dev Kit installer can lead to privilege escalation and arbitrary code execution when running the impacted installer. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://community.silabs.com/068Vm00000JUQwd |
|
Fri, 24 Jan 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 24 Jan 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | DLL hijacking vulnerabilities, caused by an uncontrolled search path in the USBXpress Dev Kit installer can lead to privilege escalation and arbitrary code execution when running the impacted installer. | |
| Title | Uncontrolled search path can lead to DLL hijacking in USBXpress Dev Kit installer | |
| Weaknesses | CWE-427 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Silabs
Published:
Updated: 2025-02-18T19:31:22.242Z
Reserved: 2024-10-03T18:32:57.369Z
Link: CVE-2024-9496
Updated: 2025-01-24T14:53:44.160Z
Status : Awaiting Analysis
Published: 2025-01-24T15:15:11.450
Modified: 2025-02-18T20:15:23.107
Link: CVE-2024-9496
No data.
OpenCVE Enrichment
No data.
EUVD