Vulnerabilities
1 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-23748 | DLL Sideloading Vulnerability in Audinate Dante Discovery (mDNSResponder.exe) Audinate Dante Discovery's mDNSResponder.exe executable improperly specifies how, from which folder, and under what conditions it loads DLLs, enabling a DLL sideloading attack (CWE-114/CWE-426). An attacker who can place a crafted malicious DLL where the legitimate executable searches for libraries can trigger it to be loaded when the binary runs; the CVSS vector (AV:L, UI:R) indicates local access and some user interaction are required to start the vulnerable process. Because the malicious code executes under the cover of a valid, legitimate executable, the attacker gains code execution with high impact on confidentiality, integrity, and availability. The flaw affects Windows hosts running Audinate's Dante Discovery component, which ships with Dante software tooling and the Dante Application Library used in professional audio networking deployments. It was added to the CISA Known Exploited Vulnerabilities catalog on 2025-02-06, confirming exploitation in the wild; EPSS puts the 30-day exploitation probability at 9.1% (95th percentile), no public PoC is known, and ransomware use is unknown. Do: Apply Audinate's mitigations or upgrade Dante Discovery / Dante Application Library to the latest vendor-recommended release per the CISA KEV required action, and discontinue use of the affected component if mitigations are unavailable. On Windows hosts, check for unexpected or unrecognized DLL files in the directory from which mDNSResponder.exe runs (and its DLL search paths), and restrict write permissions on the application folder to prevent malicious DLL placement. Given the KEV listing and 95th-percentile EPSS, prioritize patching internet-relevant and audio-control workstations in broadcast, live production, and installed-sound environments. | 7.8 | 9% | KEV |
| large≈ hundreds of thousands of Windows hosts running Audinate Dante software (Dante Controller/Discovery and Dante Application Library deployments) |