Exploitation Summary
CVE-2024-6473 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including 12345qwert123456.
AI-analyzed exploit summary This PoC demonstrates a DLL hijacking vulnerability in Yandex Browser (CVE-2024-6473) by compiling a malicious DLL that spawns a command prompt when placed in the browser's application directory. The exploit leverages an untrusted search path to execute arbitrary code upon browser startup.
Description
Yandex Browser for Desktop before 24.7.1.380 has a DLL Hijacking Vulnerability because an untrusted search path is used.
Exploits (1)
This PoC demonstrates a DLL hijacking vulnerability in Yandex Browser (CVE-2024-6473) by compiling a malicious DLL that spawns a command prompt when placed in the browser's application directory. The exploit leverages an untrusted search path to execute arbitrary code upon browser startup.
References (1)
Scores
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H