← Vulnerability feed

Vulnerability record · CVE-2022-23748 · published 17 November 2022

CVE-2022-23748: Audinate Dante mDNSResponder.exe DLL sideloading flaw

Audinate · Dante Application Library

mDNSResponder.exe in Audinate's Dante Application Library improperly specifies how it loads a DLL, including the folder and conditions, allowing a malicious DLL to be loaded. This is a DLL sideloading issue (CWE-114/CWE-426) that lets an attacker abuse a legitimate signed executable to run malicious code. It matters because the vulnerable component is part of the widely deployed Dante discovery process.

7.8 CVSS 3.1 High CISA KEV since 6 Feb 2025 EPSS 9.1% · top 4.9% CWE-114 · CWE-114CWE-426 · Untrusted search path
7.8CVSS 3.1 base score
9.1%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
5References
17 Jun 2026Last modified by NVD

Description

mDNSResponder.exe is vulnerable to DLL Sideloading attack. Executable improperly specifies how to load the DLL, from which folder and under what conditions. In these scenarios, a malicious attacker could be using the valid and legitimate executable to load malicious files.

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

high priorityThe flaw is in CISA KEV with confirmed exploitation and High CVSS impact, though it requires local access and user interaction.

What it is

mDNSResponder.exe in Audinate's Dante Application Library improperly specifies how it loads a DLL, including the folder and conditions, allowing a malicious DLL to be loaded. This is a DLL sideloading issue (CWE-114/CWE-426) that lets an attacker abuse a legitimate signed executable to run malicious code. It matters because the vulnerable component is part of the widely deployed Dante discovery process.

Impact

An attacker who can place a crafted DLL where the executable searches can execute arbitrary code in the context of the legitimate process. CVSS 3.1 rates confidentiality, integrity and availability impact as High.

Attack surface

The vector is local (AV:L) with user interaction required (UI:R) and no privileges required (PR:N), meaning the attacker needs a foothold on the host and must get the user to trigger the executable. It is not remotely reachable and does not require authentication.

Exploitation

CVE-2022-23748 was added to CISA's Known Exploited Vulnerabilities catalog on 2025-02-06, confirming active exploitation; EPSS 30-day probability is about 9.1% (95th percentile). No ransomware campaign use is documented.

What to do

  • Apply the vendor's fix per Audinate's advisory for the Dante Discovery/mDNSResponder.exe issue; if no fix is available, follow CISA guidance and discontinue use of the affected product.
  • Restrict write access to directories searched by mDNSResponder.exe so unprivileged users cannot plant DLLs.
  • Enforce application control or DLL search-order hardening (e.g., safe DLL search mode, signed DLL enforcement) on hosts running Dante software.
  • Monitor and alert on unexpected DLL loads by mDNSResponder.exe and on new DLLs appearing in its search paths.

Detection

  • Hunt for mDNSResponder.exe loading DLLs from user-writable or non-standard directories.
  • Monitor for newly created DLL files in directories adjacent to the Dante/mDNSResponder executable.
  • Alert on process creation of mDNSResponder.exe followed by network or child-process activity inconsistent with normal discovery behavior.
  • Correlate file-write events in Dante install paths with subsequent mDNSResponder.exe execution.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2022-23748 to the Known Exploited Vulnerabilities catalog on 6 February 2025 as "Dante Discovery Process Control Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 27 February 2025.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-23748 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Source: NIST National Vulnerability Database (record CVE-2022-23748), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.