Home / Vulnerabilities / CVE-2022-23748
HIGH SEVERITY
CVE-2022-23748 Audinate · Dante Discovery

Dante Discovery Process Control Vulnerability

Technical Severity

CVSS v3.1 Metrics

HIGH
7.8 / 10
Minimal Risk Critical
Vector Specification
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitation Likelihood

EPSS Prediction

11.74 %
Predictive Probability
Percentile Rank
93.5 th

Documented as more likely to be exploited than 93.5% of known CVEs.

Detection Date

Feb 06, 2025

Remediation Due

Feb 27, 2025

CISA Catalog Active

Threat Analysis

Dante Discovery contains a process control vulnerability in mDNSResponder.exe that all allows for a DLL sideloading attack. A local attacker can leverage this vulnerability in the Dante Application Library to execute arbitrary code.

Remediation Directive

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

External Intelligence