High severity7.8NVD Advisory· Published Mar 2, 2017· Updated Jun 17, 2026
CVE-2017-5235
CVE-2017-5235
Description
Rapid7 Metasploit Pro installers prior to version 4.13.0-2017022101 contain a DLL preloading vulnerability, wherein it is possible for the installer to load a malicious DLL located in the current working directory of the installer.
Affected products
3cpe:2.3:a:rapid7:metasploit:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:rapid7:metasploit:*:*:*:*:*:*:*:*range: <=4.13.0-2017012501
- (no CPE)range: <4.13.0-2017022101
- (no CPE)range: All versions prior to version 4.13.0-2017022101
Patches
Vulnerability mechanics
References
2- www.securityfocus.com/bid/96548nvdThird Party AdvisoryVDB Entry
- community.rapid7.com/community/infosec/blog/2017/03/01/multiple-vulnerabilities-affecting-four-rapid7-productsnvdMitigationVendor Advisory
News mentions
0No linked articles in our index yet.