CVE Database
/

CVE-2022-46330

Back to search

CVE-2022-46330

Published: Dec 21, 2022

Modified: Apr 16, 2025

PUBLISHED

Description

Squirrel.Windows is both a toolset and a library that provides installation and update functionality for Windows desktop applications. Installers generated by Squirrel.Windows 2.0.1 and earlier contain an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries. As a result, arbitrary code may be executed with the privilege of the user invoking the installer.

VendorProductVersions

Squirrel

Installers generated by Squirrel.Windows

affected
2.0.1 and earlier

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now