CVE-2024-6473

HIGH EXPLOITED

Yandex Browser <24.7.1.380 - DLL Hijacking

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2024-6473 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including 12345qwert123456.

AI-analyzed exploit summary This PoC demonstrates a DLL hijacking vulnerability in Yandex Browser (CVE-2024-6473) by compiling a malicious DLL that spawns a command prompt when placed in the browser's application directory. The exploit leverages an untrusted search path to execute arbitrary code upon browser startup.

Description

Yandex Browser for Desktop before 24.7.1.380 has a DLL Hijacking Vulnerability because an untrusted search path is used.

Exploits (1)

nomisec WORKING POC 1 stars
by 12345qwert123456 · poc
https://github.com/12345qwert123456/CVE-2024-6473-PoC

This PoC demonstrates a DLL hijacking vulnerability in Yandex Browser (CVE-2024-6473) by compiling a malicious DLL that spawns a command prompt when placed in the browser's application directory. The exploit leverages an untrusted search path to execute arbitrary code upon browser startup.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Yandex Browser for Desktop before 24.7.1.380
No auth needed
Prerequisites: Vulnerable Yandex Browser version installed · DLL placed in %LOCALAPPDATA%\Yandex\YandexBrowser\Application
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1

Scores

CVSS v3 7.8
EPSS 0.0072
EPSS Percentile 48.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

VulnCheck KEV 2024-09-03
CWE
CWE-426
Status published
Products (1)
yandex/yandex_browser < 24.7.1.380
Published Sep 03, 2024
Tracked Since Feb 18, 2026