CVE-2022-23748 is a DLL Sideloading vulnerability in mDNSResponder.exe, affecting Audinate Dante Application Library and Microsoft Windows. This allows an attacker to load malicious files using a legitimate executable due to improper DLL loading specifications. With a CVSS score of 7.8 (HIGH), it poses a significant risk with high impact on confidentiality, integrity, and availability, requiring user interaction but with low attack complexity. This vulnerability is actively exploited and listed in CISA's KEV catalog, despite a lack of public exploit code in Metasploit or ExploitDB, and has garnered notable community discussion and media coverage, including its use by the ToddyCat APT group.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.2.0CPE matchmatch criteria | cpe:2.3:a:audinate:dante_application_library:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.