Insecure DLL loading in Administrative Tools for Intel Network Adapters - CVE-2022-41314

 

Insecure DLL loading in Administrative Tools for Intel Network Adapters - CVE-2022-41314

Published: February 22, 2023


Vulnerability identifier: #VU72503
CSH Severity: Medium
CVSS v4: 7.4 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-41314
CWE-ID: CWE-427
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to the application loads DLL libraries in an insecure manner. A remote attacker can place a specially crafted .dll file into the folder near to installer, trick the victim into executing the installer binary and execute arbitrary code on victim's system.


Affected software

Administrative Tools for Intel Network Adapters
Non-Volatile Memory (NVM) Update Utility for Intel Ethernet Network Adapter E810 Series

How to mitigate CVE-2022-41314

Install updates from vendor's website.

Administrative Tools for Intel Network Adapters - update to 27.3
Non-Volatile Memory (NVM) Update Utility for Intel Ethernet Network Adapter E810 Series - update to 4.01

External References

Related Security Bulletins