PatchSiren cyber security CVE debrief
CVE-2017-5235 Rapid7 CVE debrief
CVE-2017-5235 is a DLL preloading issue affecting Rapid7 Metasploit Pro installers. According to the CVE description, an attacker could place a malicious DLL in the installer’s current working directory and influence what the installer loads. NVD rates the issue HIGH with CVSS 3.0 7.8, reflecting the potential for local code execution when a user runs the installer. Rapid7’s advisory references a fixed installer release and the CVE record links to vendor mitigation guidance.
- Vendor
- Rapid7
- Product
- Metasploit
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-03-02
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-03-02
- Advisory updated
- 2026-05-13
Who should care
Organizations and individuals who download, distribute, or install Rapid7 Metasploit Pro installers should care, especially where installers may be run from writable or untrusted directories. Endpoint and application deployment teams should also review whether installer staging processes could expose users to DLL search-order risks.
Technical summary
The weakness is classified as CWE-426 (Untrusted Search Path). In the described scenario, the installer may load a DLL from the current working directory rather than a trusted location, allowing a locally placed malicious library to be loaded during installation. The NVD record lists the vulnerable Metasploit product family and indicates affected versions up to a fixed release boundary, while the Rapid7 advisory provides mitigation context. The available corpus shows a version-boundary inconsistency between the CVE description and the NVD CPE entry, so version applicability should be verified against vendor guidance before making deployment decisions.
Defensive priority
High for any environment that still distributes or runs affected installers. The risk is most relevant during software installation on Windows systems where the working directory can be influenced or staged content is not trusted.
Recommended defensive actions
- Verify whether any Metasploit Pro installers in use are older than the fixed Rapid7 release referenced in the vendor advisory and replace them with the corrected version.
- Store installers in trusted, access-controlled directories and avoid running them from writable or user-controlled locations.
- Review software deployment workflows to ensure installers are launched from clean staging paths with restricted write permissions.
- If you manage endpoints, block or alert on execution of outdated installer packages and validate hashes or package provenance before distribution.
- Consult the Rapid7 advisory and the NVD record for the most current vendor guidance and applicability details.
Evidence notes
Evidence is drawn from the CVE record and NVD metadata supplied in the source corpus. The CVE description states that Rapid7 Metasploit Pro installers prior to version 4.13.0-2017022101 can load a malicious DLL from the current working directory. The NVD metadata classifies the weakness as CWE-426 and assigns CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H. The source corpus also includes a Rapid7 vendor advisory reference and a SecurityFocus BID reference. The NVD CPE version boundary shown in the corpus (4.13.0-2017012501) does not exactly match the prose description; this should be treated as a documentation inconsistency in the supplied sources, not resolved as fact here.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-5235 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-5235
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-5235 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-5235
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://community.rapid7.com/community/infosec/blog/2017/03/01/multiple-vulnerabilities-affecting-four-rapid7-products
[email protected] - Mitigation, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.