PatchSiren cyber security CVE debrief
CVE-2016-10157 Akamai CVE debrief
CVE-2016-10157 describes a DLL hijacking issue in Akamai NetSession 1.9.3.1. The application attempts to load CSUNSAPI.dll without providing a complete path, and the DLL is reported missing from the installation. That search-order behavior can let a malicious DLL be loaded instead, resulting in code execution inside the NetSession process.
- Vendor
- Akamai
- Product
- Netsession
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-01-23
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-01-23
- Advisory updated
- 2026-05-13
Who should care
Administrators and security teams responsible for systems running Akamai NetSession 1.9.3.1, endpoint hardening teams, and responders investigating unexpected DLL load behavior in Akamai processes.
Technical summary
NVD records the vulnerable CPE as akamai:netsession:1.9.3.1 and assigns a Critical CVSS 3.0 score of 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). The issue is described as Akamai NetSession loading CSUNSAPI.dll without a fully qualified path, while the DLL is absent from the installation. In practice, that creates a DLL hijacking opportunity. NVD maps the weakness to CWE-94, though the behavior is commonly discussed as a DLL search-order hijack.
Defensive priority
Critical. Remove or update affected NetSession installations as soon as possible, and treat any unexpected DLL load from the NetSession process as a high-priority investigation.
Recommended defensive actions
- Inventory systems for Akamai NetSession 1.9.3.1 and any remaining installations.
- Upgrade, replace, or uninstall the affected software using vendor-supported remediation if available.
- Apply application control and DLL-loading hardening to reduce the risk of untrusted DLLs loading into trusted processes.
- Monitor for CSUNSAPI.dll or similarly named DLLs in writable search locations and for unusual NetSession process behavior.
- Investigate endpoints for suspicious code execution or persistence associated with the NetSession process.
Evidence notes
The CVE description and NVD record both state that Akamai NetSession 1.9.3.1 loads CSUNSAPI.dll without a full path and that the DLL is missing from the installation, enabling hijacking and code injection into the process space. NVD lists a vulnerable CPE for akamai:netsession:1.9.3.1, assigns CVSS 3.0 9.8, maps the weakness to CWE-94, and cites SecurityFocus BID 95995 plus a Packet Storm third-party advisory.
Sources and references
Verified primary and authoritative sources
-
CVE-2016-10157 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-10157
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-10157 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-10157
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://packetstormsecurity.com/files/140366/Akamai-NetSession-1.9.3.1-DLL-Hijacking.html
[email protected] - Third Party Advisory, VDB Entry
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.