On versions beginning in 7.1.5 to before 7.2.3.1, a DLL...
Moderate severity
Unreviewed
Published
Feb 1, 2023
to the GitHub Advisory Database
•
Updated Feb 17, 2023
Description
Published by the National Vulnerability Database
Feb 1, 2023
Published to the GitHub Advisory Database
Feb 1, 2023
Last updated
Feb 17, 2023
On versions beginning in 7.1.5 to before 7.2.3.1, a DLL hijacking vulnerability exists in the BIG-IP Edge Client for Windows. User interaction and administrative privileges are required to exploit this vulnerability because the victim user needs to run the executable on the system and the attacker requires administrative privileges for modifying the files in the trusted search path. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
References