CVE-2021-1386
Cisco Advanced Malware Protection for Endpoints Windows Connector, ClamAV for Windows, and Immunet DLL Hijacking Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability in the dynamic link library (DLL) loading mechanism in Cisco Advanced Malware Protection (AMP) for Endpoints Windows Connector, ClamAV for Windows, and Immunet could allow an authenticated, local attacker to perform a DLL hijacking attack on an affected Windows system. To exploit this vulnerability, the attacker would need valid credentials on the system. The vulnerability is due to insufficient validation of directory search paths at run time. An attacker could exploit this vulnerability by placing a malicious DLL file on an affected system. A successful exploit could allow the attacker to execute arbitrary code with SYSTEM privileges.
Una vulnerabilidad en el mecanismo de carga de la dynamic link library (DLL) en Cisco Advanced Malware Protection (AMP) para Endpoints Windows Connector, ClamAV para Windows e Immunet, podría permitir a un atacante local autenticado llevar a cabo un ataque de secuestro DLL en un sistema Windows afectado. Para explotar esta vulnerabilidad, el atacante necesitaría credenciales válidas en el sistema. La vulnerabilidad es debido a una comprobación insuficiente de las rutas de búsqueda de directorios en tiempo de ejecución. Un atacante podría explotar esta vulnerabilidad al colocar un archivo DLL malicioso en un sistema afectado. Una explotación con éxito podría permitir al atacante ejecutar código arbitrario con privilegios SYSTEM
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2020-11-13 CVE Reserved
- 2021-04-07 CVE Published
- 2023-03-08 EPSS Updated
- 2024-11-08 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-427: Uncontrolled Search Path Element
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Advanced Malware Protection For Endpoints Search vendor "Cisco" for product "Advanced Malware Protection For Endpoints" | < 7.3.15 Search vendor "Cisco" for product "Advanced Malware Protection For Endpoints" and version " < 7.3.15" | windows |
Affected
| ||||||
Cisco Search vendor "Cisco" | Clamav Search vendor "Cisco" for product "Clamav" | < 0.103.2 Search vendor "Cisco" for product "Clamav" and version " < 0.103.2" | windows |
Affected
| ||||||
Cisco Search vendor "Cisco" | Immunet Search vendor "Cisco" for product "Immunet" | < 7.4.0 Search vendor "Cisco" for product "Immunet" and version " < 7.4.0" | windows |
Affected
|