PatchSiren

Akamai CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL Akamai CVE published 2017-01-23

CVE-2016-10157

CVE-2016-10157 describes a DLL hijacking issue in Akamai NetSession 1.9.3.1. The application attempts to load CSUNSAPI.dll without providing a complete path, and the DLL is reported missing from the installation. That search-order behavior can let a malicious DLL be loaded instead, resulting in code execution inside the NetSession process.