CVE-2024-22410 describes a DLL hijacking vulnerability in the Windows binary of the Creditcoin node, where an attacker with write access to the program files directory could replace legitimate Microsoft DLLs to execute arbitrary code. This vulnerability carries a CVSS score of 7.8 (HIGH), indicating a local attack vector with low complexity, requiring low privileges, and potentially leading to high impact on confidentiality, integrity, and availability. Despite the high CVSS score, the Creditcoin development team views this as a low-security risk, considering Windows support experimental and unofficial. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE match | cpe:2.3:a:gluwa:creditcoin:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.