A DLL hijacking vulnerability exists in the GeoVision GV-IP Device Utility desktop application. The application loads one or more dynamic-link libraries (DLLs) from an unsafe search path, allowing a local attacker to place a malicious DLL in a location searched before the legitimate library location.
A DLL hijacking vulnerability exists in the GeoVision GV-IP Device Utility desktop application. The application loads one or more dynamic-link libraries (DLLs) from an unsafe search path, allowing a local attacker to place a malicious DLL in a location searched before the legitimate library location.
为什么是这个 VPI(可解释·实验性)
VPI 计算依据
| 影响度 | 73.00 |
| 利用信号(无额外利用信号) | ×1.00 |
| VPI | 73.00 |
VPI 公式 vpi-v1