PatchSiren cyber security CVE debrief
CVE-2017-5234 Rapid7 CVE debrief
CVE-2017-5234 affects Rapid7 Insight Collector installers prior to 1.0.16. The NVD record states that the installer may load a malicious DLL from its current working directory, which can lead to code execution when a user runs the installer. NVD rates the issue HIGH with CVSS 7.8, and the CVE was published on 2017-03-02.
- Vendor
- Rapid7
- Product
- Insight Collector
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-03-02
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-03-02
- Advisory updated
- 2026-05-13
Who should care
Administrators, endpoint security teams, and anyone deploying or running Rapid7 Insight Collector installers version 1.0.15 or earlier should treat this as relevant, especially if installers may be launched from writable or untrusted directories.
Technical summary
NVD maps CVE-2017-5234 to CWE-426 and assigns CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H. The vulnerable installer can resolve a DLL from the current working directory, so a malicious library placed alongside the installer may be loaded during installation. The supplied NVD references point to a Rapid7 vendor advisory and a third-party advisory entry; the corpus indicates mitigation by moving to version 1.0.16 or later.
Defensive priority
High. The impact is severe, but exploitation requires a local installer launch and user interaction. Prioritize upgrading affected systems and controlling where the installer is run.
Recommended defensive actions
- Upgrade Rapid7 Insight Collector to version 1.0.16 or later.
- Do not run the installer from directories that contain untrusted or attacker-writable files.
- Use a trusted, controlled staging directory for installer execution.
- Remove suspicious DLLs from the working directory before launching the installer.
- Obtain installers only from Rapid7-approved sources and restrict who can place files in installation paths.
Evidence notes
The supplied NVD metadata says Rapid7 Insight Collector installers through 1.0.15 are affected and maps the issue to CWE-426. NVD also references the Rapid7 community advisory and a SecurityFocus entry. The record was published on 2017-03-02 and later modified on 2026-05-13; those dates describe record timing, not a new vulnerability date.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-5234 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-5234
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-5234 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-5234
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://community.rapid7.com/community/infosec/blog/2017/03/01/multiple-vulnerabilities-affecting-four-rapid7-products
[email protected] - Mitigation, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.