Insecure DLL loading in Administrative Tools for Intel Network Adapters - CVE-2022-41314
Published: February 22, 2023
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to the application loads DLL libraries in an insecure manner. A remote attacker can place a specially crafted .dll file into the folder near to installer, trick the victim into executing the installer binary and execute arbitrary code on victim's system.
Affected software
Non-Volatile Memory (NVM) Update Utility for Intel Ethernet Network Adapter E810 Series
How to mitigate CVE-2022-41314
Non-Volatile Memory (NVM) Update Utility for Intel Ethernet Network Adapter E810 Series - update to 4.01