vulnerability
Rapid7 Insight Agent: CVE-2017-5252: Insight Agent on Windows is vulnerable to loading malicious libraries placed in its dependency search path
Severity | CVSS | Published | Added | Modified |
---|---|---|---|---|
6 | (AV:L/AC:L/Au:S/C:C/I:C/A:C) | Oct 6, 2017 | Oct 6, 2017 | Feb 18, 2025 |
Severity
6
CVSS
(AV:L/AC:L/Au:S/C:C/I:C/A:C)
Published
Oct 6, 2017
Added
Oct 6, 2017
Modified
Feb 18, 2025
Description
Insight Agent on Windows systems searches for local dependencies in several locations, including in directories in the system PATH variable. As this can include arbitrary directories, and the Agent doesn't specify the directories to search, an attacker with local admin access could place a (potentially malicious) DLL in a directory in that path, causing the Agent to load that library.
Solution(s)
rapid7-insightagent-1_4_68-kb2533623rapid7-insightagent-1_4_68

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.