CVE-2021-38469

CRITICAL

Auvesy versiondog <= 8.0.0 - DLL Hijacking

Title source: llm
STIX 2.1

Description

Many of the services used by the affected product do not specify full paths for the DLLs they are loading. An attacker can exploit the uncontrolled search path by implanting their own DLL near the affected product’s binaries, thus hijacking the loaded DLL.

References (1)

Core 1
Core References
Patch, Third Party Advisory, US Government Resource x_refsource_confirm
https://us-cert.cisa.gov/ics/advisories/icsa-21-292-01

Scores

CVSS v3 9.1
EPSS 0.0060
EPSS Percentile 43.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Details

CWE
CWE-427
Status published
Products (1)
auvesy/versiondog < 8.0.0
Published Oct 22, 2021
Tracked Since Feb 18, 2026