CVE-2023-41782 LOW

CVE-2023-41782: DLL Hijacking Vulnerability in ZTE ZXCLOUD iRAI

Vendor Zte
Product ZXCLOUD iRAI
Weakness CWE-20 · Input validation
Published January 5, 2024
Last update September 17, 2024

CVSS base score

3.9/10
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction Required
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L

What the vulnerability does

01Description

There is a DLL hijacking vulnerability in ZTE ZXCLOUD iRAI, an attacker could place a fake DLL file in a specific directory and successfully exploit this vulnerability to execute malicious code.

Key dates

02Disclosure timeline

January 5, 2024 CVE published
September 17, 2024 Record updated