CVE-2024-9499

HIGH

USBXpress Win 98SE Dev Kit - Privilege Escalation

Title source: llm
STIX 2.1

Description

DLL hijacking vulnerabilities, caused by an uncontrolled search path in the USBXpress Win 98SE Dev Kit installer can lead to privilege escalation and arbitrary code execution when running the impacted installer.

References (1)

Core 1
Core References
Various Sources vendor-advisory permissions-required
https://community.silabs.com/068Vm00000JUQwd

Scores

CVSS v3 8.6
EPSS 0.0023
EPSS Percentile 14.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-427
Status published
Products (1)
silabs.com/USBXpress Win 98SE Dev Kit < 2.42
Published Jan 24, 2025
Tracked Since Feb 18, 2026