Executive brief
Akamai NetSession, a software component used to speed up the download of large files and streams, contains a security flaw that allows for unauthorized code execution. By placing a malicious file in a specific location, an attacker can take control of the NetSession process. This could lead to a full compromise of the user's system, potentially allowing attackers to steal data or disrupt operations.
Technical details
Akamai NetSession 1.9.3.1 is vulnerable to DLL hijacking (CWE-94) due to an insecure search path when attempting to load the 'CSUNSAPI.dll' library. The application fails to provide a fully qualified path to the DLL, and because the file is missing from the default installation, the operating system searches through the standard search order. An attacker can place a malicious version of this DLL in a directory searched by the application to achieve arbitrary code execution within the context of the NetSession process. While the NVD classifies the attack vector as network, DLL hijacking typically requires a local presence or a remote file share to place the malicious library.
Affected products
- Akamai NetSession 1.9.3.1
Timeline
- 2017-01-23: advisory: NVD published the vulnerability details.