Junglewise Threat Intelligence

CVE-2022-23748: Dante Discovery Process Control Vulnerability

CVE-2022-23748 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2025-02-06

Executive brief

The Dante Discovery process (mDNSResponder.exe) is vulnerable to a DLL sideloading attack due to improper path specification when loading DLL files. A local attacker can exploit this by placing a malicious DLL in a directory searched by the application, leading to arbitrary code execution.

Affected products

  • Audinate Dante Application Library up to (including) 1.2.0
  • Audinate Dante Enabled Zoom Rooms 1.3.0.0

Timeline

  • 2022-11-17: disclosed: NVD Published Date
  • 2025-02-06: kev added: Added to CISA Known Exploited Vulnerabilities Catalog