Vulnerability record · CVE-2022-23748 · published 17 November 2022
CVE-2022-23748: Audinate Dante mDNSResponder.exe DLL sideloading flaw
Audinate · Dante Application Library
mDNSResponder.exe in Audinate's Dante Application Library improperly specifies how it loads a DLL, including the folder and conditions, allowing a malicious DLL to be loaded. This is a DLL sideloading issue (CWE-114/CWE-426) that lets an attacker abuse a legitimate signed executable to run malicious code. It matters because the vulnerable component is part of the widely deployed Dante discovery process.
Description
mDNSResponder.exe is vulnerable to DLL Sideloading attack. Executable improperly specifies how to load the DLL, from which folder and under what conditions. In these scenarios, a malicious attacker could be using the valid and legitimate executable to load malicious files.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw is in CISA KEV with confirmed exploitation and High CVSS impact, though it requires local access and user interaction.
What it is
mDNSResponder.exe in Audinate's Dante Application Library improperly specifies how it loads a DLL, including the folder and conditions, allowing a malicious DLL to be loaded. This is a DLL sideloading issue (CWE-114/CWE-426) that lets an attacker abuse a legitimate signed executable to run malicious code. It matters because the vulnerable component is part of the widely deployed Dante discovery process.
Impact
An attacker who can place a crafted DLL where the executable searches can execute arbitrary code in the context of the legitimate process. CVSS 3.1 rates confidentiality, integrity and availability impact as High.
Attack surface
The vector is local (AV:L) with user interaction required (UI:R) and no privileges required (PR:N), meaning the attacker needs a foothold on the host and must get the user to trigger the executable. It is not remotely reachable and does not require authentication.
Exploitation
CVE-2022-23748 was added to CISA's Known Exploited Vulnerabilities catalog on 2025-02-06, confirming active exploitation; EPSS 30-day probability is about 9.1% (95th percentile). No ransomware campaign use is documented.
What to do
- Apply the vendor's fix per Audinate's advisory for the Dante Discovery/mDNSResponder.exe issue; if no fix is available, follow CISA guidance and discontinue use of the affected product.
- Restrict write access to directories searched by mDNSResponder.exe so unprivileged users cannot plant DLLs.
- Enforce application control or DLL search-order hardening (e.g., safe DLL search mode, signed DLL enforcement) on hosts running Dante software.
- Monitor and alert on unexpected DLL loads by mDNSResponder.exe and on new DLLs appearing in its search paths.
Detection
- Hunt for mDNSResponder.exe loading DLLs from user-writable or non-standard directories.
- Monitor for newly created DLL files in directories adjacent to the Dante/mDNSResponder executable.
- Alert on process creation of mDNSResponder.exe followed by network or child-process activity inconsistent with normal discovery behavior.
- Correlate file-write events in Dante install paths with subsequent mDNSResponder.exe execution.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2022-23748 to the Known Exploited Vulnerabilities catalog on 6 February 2025 as "Dante Discovery Process Control Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 27 February 2025.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2022-23748 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Source: NIST National Vulnerability Database (record CVE-2022-23748), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.