VYPR
High severity7.8NVD Advisory· Published Mar 2, 2017· Updated May 13, 2026

CVE-2017-5235

CVE-2017-5235

Description

Rapid7 Metasploit Pro installers prior to version 4.13.0-2017022101 contain a DLL preloading vulnerability, wherein it is possible for the installer to load a malicious DLL located in the current working directory of the installer.

Affected products

2
  • cpe:2.3:a:rapid7:metasploit:*:*:*:*:*:*:*:*
    Range: <=4.13.0-2017012501
  • Rapid7/Metasploit Prov5
    Range: All versions prior to version 4.13.0-2017022101

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.