PatchSiren cyber security CVE debrief
CVE-2017-5232 Rapid7 CVE debrief
CVE-2017-5232 is a DLL preloading weakness in Rapid7 Nexpose installers affecting versions prior to 6.4.24. If the installer is launched from a directory containing a malicious DLL with a name the installer resolves, it may load that file during installation. The issue was publicly disclosed on 2017-03-02 and carries a high CVSS 3.0 score because successful abuse can impact confidentiality, integrity, and availability.
- Vendor
- Rapid7
- Product
- Nexpose
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-03-02
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-03-02
- Advisory updated
- 2026-05-13
Who should care
Security teams, Windows administrators, and endpoint or software deployment teams that run Rapid7 Nexpose installers should care most. The risk is highest where installers are executed from writable or user-controlled directories, or where deployment processes do not tightly control the installer working directory.
Technical summary
NVD classifies the weakness as CWE-426 (Untrusted Search Path). The affected product range is Rapid7 Nexpose versions up to and including 6.4.23, with 6.4.24 identified as the fixed release in the provided vendor context. The CVSS vector indicates local attack conditions with low complexity, no privileges required, user interaction required, and high impact if a malicious DLL is loaded during installation.
Defensive priority
High for any environment still using affected installer versions or re-running archived installers. This is a pre-installation execution risk, so it should be addressed before software deployment activities continue.
Recommended defensive actions
- Upgrade Rapid7 Nexpose installers and deployment media to version 6.4.24 or later.
- Do not run installers from writable or shared directories; use a trusted, read-only staging path.
- Review deployment scripts and packaging workflows to ensure the installer working directory cannot be influenced by untrusted users.
- Restrict write access on systems used to stage or launch installers.
- Verify installer integrity from vendor sources before use, and remove outdated installer copies from internal repositories.
- Inventory any remaining Nexpose installer artifacts that predate 6.4.24 and replace them with fixed versions.
Evidence notes
The supplied NVD record lists affected Nexpose versions through 6.4.23 and maps the issue to CWE-426. The Rapid7 vendor advisory referenced in NVD provides mitigation context, and the CVE publication date supplied is 2017-03-02. No KEV entry was provided in the supplied enrichment.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-5232 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-5232
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-5232 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-5232
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://community.rapid7.com/community/infosec/blog/2017/03/01/multiple-vulnerabilities-affecting-four-rapid7-products
[email protected] - Mitigation, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.