PT-2024-31825 · Vegabird · Vegabird Yaazhini

Iulian Florea

·

Published

2024-09-30

·

Updated

2024-10-10

·

CVE-2024-45873

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions VegaBird Yaazhini version 2.0.2
Description A DLL hijacking issue allows attackers to execute arbitrary code and maintain persistence by placing a crafted DLL file in the same directory as Yaazhini.exe. This enables them to potentially gain control over the system.
Recommendations For VegaBird Yaazhini version 2.0.2, consider removing or restricting access to the vulnerable DLL files as a temporary workaround until a patch is available. Restrict the ability to place crafted DLL files in the same directory as Yaazhini.exe to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2024-45873

Affected Products

Vegabird Yaazhini