PT-2024-41365 · Yandex +1 · Telemost +2

Published

2024-09-20

·

Updated

2025-08-26

·

CVE-2024-12168

CVSS v4.0
8.4
VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Yandex Telemost versions prior to 2.7.0
Description The issue is related to the use of an untrusted search path, which may allow an attacker to execute arbitrary code. This can be exploited through a DLL hijacking vulnerability.
Recommendations For versions prior to 2.7.0, update to version 2.7.0 or later to resolve the issue.

Fix

Untrusted Search Path

Weakness Enumeration

Related Identifiers

BDU:2025-05686
CVE-2024-12168

Affected Products

Telemost
Yandex Telemost
Яндекс.Телемост