Security Advisory

CVE-2021-26807

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2021-04-30 10:53:04
Last updated 2024-08-03 20:33:40
Assigner mitre
State PUBLISHED

Description

GalaxyClient version 2.0.28.9 loads unsigned DLLs such as zlib1.dll, libgcc_s_dw2-1.dll and libwinpthread-1.dll from PATH, which allows an attacker to potentially run code locally through unsigned DLL loading.