PatchSiren

PatchSiren cyber security CVE debrief

CVE-2017-5235 Rapid7 CVE debrief

CVE-2017-5235 is a DLL preloading issue affecting Rapid7 Metasploit Pro installers. According to the CVE description, an attacker could place a malicious DLL in the installer’s current working directory and influence what the installer loads. NVD rates the issue HIGH with CVSS 3.0 7.8, reflecting the potential for local code execution when a user runs the installer. Rapid7’s advisory references a fixed installer release and the CVE record links to vendor mitigation guidance.

Vendor
Rapid7
Product
Metasploit
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2017-03-02
Original CVE updated
2026-05-13
Advisory published
2017-03-02
Advisory updated
2026-05-13

Who should care

Organizations and individuals who download, distribute, or install Rapid7 Metasploit Pro installers should care, especially where installers may be run from writable or untrusted directories. Endpoint and application deployment teams should also review whether installer staging processes could expose users to DLL search-order risks.

Technical summary

The weakness is classified as CWE-426 (Untrusted Search Path). In the described scenario, the installer may load a DLL from the current working directory rather than a trusted location, allowing a locally placed malicious library to be loaded during installation. The NVD record lists the vulnerable Metasploit product family and indicates affected versions up to a fixed release boundary, while the Rapid7 advisory provides mitigation context. The available corpus shows a version-boundary inconsistency between the CVE description and the NVD CPE entry, so version applicability should be verified against vendor guidance before making deployment decisions.

Defensive priority

High for any environment that still distributes or runs affected installers. The risk is most relevant during software installation on Windows systems where the working directory can be influenced or staged content is not trusted.

Recommended defensive actions

  • Verify whether any Metasploit Pro installers in use are older than the fixed Rapid7 release referenced in the vendor advisory and replace them with the corrected version.
  • Store installers in trusted, access-controlled directories and avoid running them from writable or user-controlled locations.
  • Review software deployment workflows to ensure installers are launched from clean staging paths with restricted write permissions.
  • If you manage endpoints, block or alert on execution of outdated installer packages and validate hashes or package provenance before distribution.
  • Consult the Rapid7 advisory and the NVD record for the most current vendor guidance and applicability details.

Evidence notes

Evidence is drawn from the CVE record and NVD metadata supplied in the source corpus. The CVE description states that Rapid7 Metasploit Pro installers prior to version 4.13.0-2017022101 can load a malicious DLL from the current working directory. The NVD metadata classifies the weakness as CWE-426 and assigns CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H. The source corpus also includes a Rapid7 vendor advisory reference and a SecurityFocus BID reference. The NVD CPE version boundary shown in the corpus (4.13.0-2017012501) does not exactly match the prose description; this should be treated as a documentation inconsistency in the supplied sources, not resolved as fact here.

Sources and references

Verified primary and authoritative sources

  • CVE-2017-5235 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2017-5235

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2017-5235 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2017-5235

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.