CVE-2017-5235: RAPID7 Metasploit
High severity, CVSS 7.8. EPSS: 0.9% chance of exploitation in the next 30 days.
Rapid7 Metasploit Pro installers prior to version 4.13.0-2017022101 contain a DLL preloading vulnerability, wherein it is possible for the installer to load a malicious DLL located in the current working directory of the installer.
Affected products
- RAPID7 Metasploit: up to and including 4.13.0-2017012501
Published 2017-03-02. Last modified 2026-06-17.