CVE-2022-23748

Vulnerability updated 4 months ago (2024-05-04T23:18:09.633Z)
Download STIX
Preview STIX
CVE-2022-23748 is a software vulnerability, specifically a flaw in the design or implementation of Audinate's Dante Discovery software. This vulnerability allows for malicious exploitation via DLL side-loading schemes, where the affected software, due to its flawed design, loads and executes a malicious DLL file instead of the legitimate one. The particular DLL targeted in this case is dal_keepalives.dll, which is hijacked by threat actors to exploit the vulnerability. The exploit was utilized as part of a cyber campaign that leverages spear-phishing emails to deliver archive files containing a digitally signed executable and a malicious DLL. The executable is named to match the context of the email, thereby tricking the recipient into thinking it is a legitimate attachment. Once the archive is opened, the malicious DLL exploits CVE-2022-23748 in Dante Discovery software to side-load a malware named "CurKeep" onto the victim's system. This campaign uses a sophisticated approach combining social engineering (spear-phishing) with a technical exploit (DLL side-loading via CVE-2022-23748). It highlights the importance of maintaining up-to-date software patches and educating users about the dangers of opening unsolicited email attachments. Users of Audinate's Dante Discovery software should ensure they have applied any available patches to mitigate this vulnerability and prevent potential compromise of their systems.
Description last updated: 2024-05-04T22:24:01.949Z
What's your take? (Question 1 of 0)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Phishing
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the CVE-2022-23748 Vulnerability was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
CERT-EU
a year ago
ToddyCat hackers use 'disposable' malware to target Asian telecoms
InfoSecurity-magazine
a year ago
Chinese APT ToddyCat Targets Asian Telecoms, Governments
CERT-EU
a year ago
Chinese 'Stayin' Alive' Attacks Dance Onto Targets With Dumb Malware
Checkpoint
a year ago
Stayin’ Alive - Targeted Attacks Against Telecoms and Government Ministries in Asia - Check Point Research