CVE Database
/

CVE-2017-6329

Back to search

CVE-2017-6329

Published: Aug 21, 2017

Modified: Sep 16, 2024

PUBLISHED

Description

Symantec VIP Access for Desktop prior to 2.2.4 can be susceptible to a DLL Pre-Loading vulnerability. These types of issues occur when an application looks to call a DLL for execution and an attacker provides a malicious DLL to use instead. Depending on how the application is configured, the application will generally follow a specific search path to locate the DLL. The exploitation of the vulnerability manifests as a simple file write (or potentially an over-write) which results in a foreign executable running under the context of the application.

VendorProductVersions

Symantec Corporation

VIP Access for Desktop

affected
prior to 2.2.4

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now