PT-2024-31826 · Vegabird · Vegabird Vooki

Iulian Florea

·

Published

2024-09-30

·

Updated

2024-10-10

·

CVE-2024-45874

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions VegaBird Vooki version 5.2.9
Description A DLL hijacking issue allows attackers to execute arbitrary code and maintain persistence by placing a crafted DLL file in the same directory as Vooki.exe. This enables attackers to potentially gain control over the system.
Recommendations For VegaBird Vooki version 5.2.9, consider removing or restricting access to the directory where Vooki.exe is located to prevent attackers from placing malicious DLL files. As a temporary workaround, monitor the directory for any suspicious DLL files and remove them immediately. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2024-45874

Affected Products

Vegabird Vooki