CVE-2021-36631

Untrusted search path vulnerability in Baidunetdisk Version 7.4.3 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Configurations

Configuration 1 (hide)

cpe:2.3:a:baidu:baidunetdisk:*:*:*:*:*:*:*:*

History

21 Nov 2024, 06:13

Type Values Removed Values Added
Summary
  • (es) Vulnerabilidad de ruta de búsqueda no confiable en Baidunetdisk versión 7.4.3 y anteriores permite a un atacante obtener privilegios a través de una DLL de Troyano en un directorio no especificado.
References () https://github.com/shigophilo/CVE/blob/main/Baidunetdisk%20Version%207.4.3%20dll%20hijack.md - Exploit, Third Party Advisory () https://github.com/shigophilo/CVE/blob/main/Baidunetdisk%20Version%207.4.3%20dll%20hijack.md - Exploit, Third Party Advisory

Information

Published : 2022-12-22 02:15

Updated : 2025-04-16 15:15


NVD link : CVE-2021-36631

Mitre link : CVE-2021-36631

CVE.ORG link : CVE-2021-36631


JSON object : View

Products Affected

baidu

  • baidunetdisk
CWE
CWE-427

Uncontrolled Search Path Element