CVE-2017-11748: Softonic Spider Player

High severity, CVSS 7.8. EPSS: 0.8% chance of exploitation in the next 30 days.

VIT Spider Player 2.5.3 has an untrusted search path, allowing DLL hijacking via a Trojan horse dwmapi.dll, olepro32.dll, dsound.dll, or AUDIOSES.dll file.

Affected products

  • Softonic Spider Player: version 2.5.3 only

Published 2017-07-30. Last modified 2026-06-17.