PatchSiren

PatchSiren cyber security CVE debrief

CVE-2017-5234 Rapid7 CVE debrief

CVE-2017-5234 affects Rapid7 Insight Collector installers prior to 1.0.16. The NVD record states that the installer may load a malicious DLL from its current working directory, which can lead to code execution when a user runs the installer. NVD rates the issue HIGH with CVSS 7.8, and the CVE was published on 2017-03-02.

Vendor
Rapid7
Product
Insight Collector
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2017-03-02
Original CVE updated
2026-05-13
Advisory published
2017-03-02
Advisory updated
2026-05-13

Who should care

Administrators, endpoint security teams, and anyone deploying or running Rapid7 Insight Collector installers version 1.0.15 or earlier should treat this as relevant, especially if installers may be launched from writable or untrusted directories.

Technical summary

NVD maps CVE-2017-5234 to CWE-426 and assigns CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H. The vulnerable installer can resolve a DLL from the current working directory, so a malicious library placed alongside the installer may be loaded during installation. The supplied NVD references point to a Rapid7 vendor advisory and a third-party advisory entry; the corpus indicates mitigation by moving to version 1.0.16 or later.

Defensive priority

High. The impact is severe, but exploitation requires a local installer launch and user interaction. Prioritize upgrading affected systems and controlling where the installer is run.

Recommended defensive actions

  • Upgrade Rapid7 Insight Collector to version 1.0.16 or later.
  • Do not run the installer from directories that contain untrusted or attacker-writable files.
  • Use a trusted, controlled staging directory for installer execution.
  • Remove suspicious DLLs from the working directory before launching the installer.
  • Obtain installers only from Rapid7-approved sources and restrict who can place files in installation paths.

Evidence notes

The supplied NVD metadata says Rapid7 Insight Collector installers through 1.0.15 are affected and maps the issue to CWE-426. NVD also references the Rapid7 community advisory and a SecurityFocus entry. The record was published on 2017-03-02 and later modified on 2026-05-13; those dates describe record timing, not a new vulnerability date.

Sources and references

Verified primary and authoritative sources

  • CVE-2017-5234 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2017-5234

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2017-5234 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2017-5234

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.