CVE-2016-4802

Description

Multiple untrusted search path vulnerabilities in cURL and libcurl before 7.49.1, when built with SSPI or telnet is enabled, allow local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse (1) security.dll, (2) secur32.dll, or (3) ws2_32.dll in the application or current working directory.

Risk Information

Base Score
7.8
MODERATE
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.612

Associated Vulnerability

VulnerabilityOS Platform
Vulnerability CVE-2016-4802 are affected in Curl For Windows 7.49.0Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.49.0Windows
Vulnerabilities CVE-2016-4802 are fixed in Curl For Windows 7.49.1Windows
CVE-2016-4802NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234