SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2022-23748

Dante Discovery Process Control Vulnerability

KEVHIGH 7.8EPSS 9.09%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 27 February 2025). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

mDNSResponder.exe is vulnerable to DLL Sideloading attack. Executable improperly specifies how to load the DLL, from which folder and under what conditions. In these scenarios, a malicious attacker could be using the valid and legitimate executable to load malicious files.

CVSS 3.1
7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS
9.09% probability · 95th percentile
CISA KEV
Listed 6 February 2025 · due 27 February 2025
Weakness
CWE-114, CWE-426
Affected
audinate/dante application library
Source
cve@checkpoint.com

CISA notes

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. https://www.getdante.com/support/faq/audinate-response-to-dante-discovery-mdnsresponder-exe-security-issue-cve-2022-23748/ ; https://nvd.nist.gov/vuln/detail/CVE-2022-23748

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.