LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2022-23748: Dante Discovery Process Control Vulnerability

RBRecent Breaches Vulnerability Intelligence·Feb 6, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Feb 27, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2022-23748 to its Known Exploited Vulnerabilities catalog on Feb 6, 2025, with a federal patch deadline of Feb 27, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Dante Discovery contains a process control vulnerability in mDNSResponder.exe that all allows for a DLL sideloading attack. A local attacker can leverage this vulnerability in the Dante Application…

CVE-2022-23748 is a process control vulnerability in Audinate Dante Discovery that enables a local attacker to perform a DLL sideloading attack against mDNSResponder.exe. By leveraging this issue in the Dante Application Library, the attacker can execute arbitrary code on the system. This matters because Dante Discovery is commonly used in professional audio networking environments; successful abuse could allow a local threat actor to run code with the privileges of the affected process, potentially leading to further compromise of the host.

Public detail is limited to the CISA description of the flaw class and impact. Confirm exact product scope, fixed releases, and any additional technical notes against the vendor advisory before taking action.

How it works

The vulnerability is classified as CWE-114 (Process Control). In this class of issue, an application fails to properly control how external code modules (such as DLLs) are loaded into a process. Here, the affected component is mDNSResponder.exe within Dante Discovery / the Dante Application Library.

A local attacker who can place a malicious DLL in a location searched by the process can cause mDNSResponder.exe to load and execute that DLL instead of the legitimate library. This is a classic DLL sideloading technique. No remote exploitation path is described in the available facts; the attack requires local access or the ability to write to a directory that the process consults for libraries. Specifics of search-order hijacking or exact load paths must be confirmed against the vendor advisory; do not assume unstated mechanics.

Am I affected? How to find it in your systems

Audinate Dante Discovery is typically installed on Windows hosts that participate in Dante audio networks—workstations, servers, or dedicated audio appliances running Dante software or the Dante Application Library. Inventory systems that handle professional audio routing, live-sound consoles, broadcast facilities, or AV-over-IP infrastructure.

How to remediate

Patch first. Apply the vendor-supplied update or mitigation instructions for Dante Discovery as named in the official Audinate advisory. CISA’s required action is to apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

If you can't patch immediately

Until the vendor update can be applied, reduce the attack surface with compensating controls appropriate to a local DLL-sideloading flaw.

If your data may have been exposed

Actively exploited local code-execution vulnerabilities can be used as a foothold for broader compromise, including data theft or lateral movement. Known ransomware use of this specific CVE is not documented. If you suspect the vulnerability was leveraged, treat the host as potentially compromised: isolate it, preserve forensic evidence, and perform a full incident-response investigation. As a routine hygiene step, you can run a free exposure scan of organizational email addresses against known breach data sets to check whether credentials or other information have already appeared in public breach corpora.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedAudinate · Dante Discovery
WeaknessCWE-114
Added to CISA KEVFeb 6, 2025
Federal patch deadlineFeb 27, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities