CVE-2022-23748
High CVSS 7.8 Known exploitedPublished 2022-11-17 · last changed 2026-06-17 · added to CISA KEV 2025-02-06
The fix
We hold no Microsoft remediation data for CVE-2022-23748, which normally means it is not a Windows CVE. For non-Microsoft software the fix is the vendor's own updated release, and the affected versions are listed below.
What it is
mDNSResponder.exe is vulnerable to DLL Sideloading attack. Executable improperly specifies how to load the DLL, from which folder and under what conditions. In these scenarios, a malicious attacker could be using the valid and legitimate executable to load malicious files.
Sources
CVSS vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H