PT-2023-1379 · F5 · Big-Ip Edge Client
Published
2023-02-01
·
Updated
2023-10-04
·
CVE-2023-22283
CVSS v3.1
6.5
Medium
| Vector | AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
BIG-IP Edge Client for Windows versions 7.1.5 through 7.2.3.1
Description
The issue is related to a DLL hijacking vulnerability in the BIG-IP Edge Client for Windows. Exploitation of this vulnerability may allow an attacker to execute arbitrary commands. User interaction and administrative privileges are required to exploit this vulnerability, as the victim user needs to run the executable on the system and the attacker requires administrative privileges for modifying the files in the trusted search path.
Recommendations
For versions 7.1.5 through 7.2.3.1, update to a version after 7.2.3.1 to resolve the issue. As a temporary workaround, consider restricting access to the trusted search path to minimize the risk of exploitation. Additionally, avoid running the executable on the system unless necessary, and ensure that administrative privileges are properly secured to prevent unauthorized modifications.
Fix
Uncontrolled Search Path Element
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Big-Ip Edge Client