ZeroHour

CVE-2022-23748

KEVlarge1

DLL Sideloading Vulnerability in Audinate Dante Discovery (mDNSResponder.exe)

CISA: Dante Discovery Process Control Vulnerability

CVSS 3.1
7.8 high
EPSS
9%p95
Published
()
KEV added
AI analysis

Audinate Dante Discovery's mDNSResponder.exe executable improperly specifies how, from which folder, and under what conditions it loads DLLs, enabling a DLL sideloading attack (CWE-114/CWE-426). An attacker who can place a crafted malicious DLL where the legitimate executable searches for libraries can trigger it to be loaded when the binary runs; the CVSS vector (AV:L, UI:R) indicates local access and some user interaction are required to start the vulnerable process. Because the malicious code executes under the cover of a valid, legitimate executable, the attacker gains code execution with high impact on confidentiality, integrity, and availability. The flaw affects Windows hosts running Audinate's Dante Discovery component, which ships with Dante software tooling and the Dante Application Library used in professional audio networking deployments. It was added to the CISA Known Exploited Vulnerabilities catalog on 2025-02-06, confirming exploitation in the wild; EPSS puts the 30-day exploitation probability at 9.1% (95th percentile), no public PoC is known, and ransomware use is unknown.

What to do: Apply Audinate's mitigations or upgrade Dante Discovery / Dante Application Library to the latest vendor-recommended release per the CISA KEV required action, and discontinue use of the affected component if mitigations are unavailable. On Windows hosts, check for unexpected or unrecognized DLL files in the directory from which mDNSResponder.exe runs (and its DLL search paths), and restrict write permissions on the application folder to prevent malicious DLL placement. Given the KEV listing and 95th-percentile EPSS, prioritize patching internet-relevant and audio-control workstations in broadcast, live production, and installed-sound environments.

Affected
Audinate Dante Discovery (Dante Application Library component, mDNSResponder.exe)
Estimated exposure
large≈ hundreds of thousands of Windows hosts running Audinate Dante software (Dante Controller/Discovery and Dante Application Library deployments) — Dante is the de facto standard audio-over-IP technology in professional audio, live sound and broadcast, embedded in devices from hundreds of manufacturers, and virtually every Dante deployment includes at least one Windows control machine…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

mDNSResponder.exe is vulnerable to DLL Sideloading attack. Executable improperly specifies how to load the DLL, from which folder and under what conditions. In these scenarios, a malicious attacker could be using the valid and legitimate executable to load malicious files.

CISA Known Exploited Vulnerability
Affected
Audinate Dante Discovery
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
audinate
Products
dante application library
Weakness
CWE-114, CWE-426
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news