Fixed Intel

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Deadline: Feb 27, 2025

CVE-2022-23748

High
EPSS 11.7%CISA KEV
Audinate/Dante Discovery

Description

Dante Discovery contains a process control vulnerability in mDNSResponder.exe that all allows for a DLL sideloading attack. A local attacker can leverage this vulnerability in the Dante Application Library to execute arbitrary code.

EPSS — Exploit Probability

11.7%

Higher than 93.6% of all CVEs

Required Action

https://www.getdante.com/support/faq/audinate-response-to-dante-discovery-mdnsresponder-exe-security-issue-cve-2022-23748/ ; https://nvd.nist.gov/vuln/detail/CVE-2022-23748

Risk Assessment

ELEVATED
In CISA KEV

Details

Severity
High
EPSS
11.7%
CISA KEV
Yes
Ransomware
Unknown
Articles
0

Timeline

Published

Feb 6, 2025

Added to KEV

Feb 6, 2025

Remediation Due

Feb 27, 2025

Affected Product

Audinate

Dante Discovery

View all Audinate CVEs