PT-2017-7775 · Akamai · Akamai Netsession
Published
2017-01-23
·
Updated
2017-02-07
·
CVE-2016-10157
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Akamai NetSession version 1.9.3.1
Description
The issue is related to DLL Hijacking, where Akamai NetSession tries to load
CSUNSAPI.dll without providing the complete path. This is exacerbated by the absence of the mentioned DLL from the installation, allowing for DLL hijacking and potential code injection within the Akamai NetSession process space.Recommendations
For Akamai NetSession version 1.9.3.1, consider restricting the loading of DLLs to only those with fully specified paths to mitigate the risk of DLL hijacking. As a temporary workaround, ensure that no malicious
CSUNSAPI.dll is loaded by the application. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Akamai Netsession