CVE-2022-23748 is a DLL sideloading vulnerability in mDNSResponder.exe from Audinate Dante Application Library. Despite being listed in CISA KEV, this is a local attack requiring user interaction to execute the malicious DLL alongside the legitimate executable.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: USER_INTERACTION
CVE Published: 2022-11-17
Added to CISA KEV: 2025-02-06 812 DAYS BETWEEN CVE AND KEV
CVE-2022-23748 is a security vulnerability in the `mDNSResponder.exe` component of Audinate’s Dante Application Library for Windows (versions 1.2.0 and earlier).
Details of CVE-2022-23748 The Flaw:mDNSResponder.exe does not properly specify the folder where its DLLs should be loaded from. Specifically, when this executable starts, it searches for some DLL files in the same directory it is launched from, or in the directory set as the application's working di…
mDNSResponder.exe is vulnerable to DLL Sideloading attack. Executable improperly specifies how to load the DLL, from which folder and under what conditions.