DLL hijacking vulnerabilities, caused by an uncontrolled search path in the USBXpress 4 SDK
installer can lead to privilege escalation and arbitrary code execution when running the impacted installer.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://community.silabs.com/068Vm00000JUQwd |
![]() ![]() |
History
Fri, 24 Jan 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 24 Jan 2025 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | DLL hijacking vulnerabilities, caused by an uncontrolled search path in the USBXpress 4 SDK installer can lead to privilege escalation and arbitrary code execution when running the impacted installer. | |
Title | Uncontrolled search path can lead to DLL hijacking in USBXpress 4 SDK installer | |
Weaknesses | CWE-427 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Silabs
Published: 2025-01-24T14:38:57.451Z
Updated: 2025-01-27T18:13:06.272Z
Reserved: 2024-10-03T18:32:58.590Z
Link: CVE-2024-9497

Updated: 2025-01-24T14:50:25.069Z

Status : Received
Published: 2025-01-24T15:15:11.620
Modified: 2025-01-24T15:15:11.620
Link: CVE-2024-9497

No data.