VendorsCiscopacket_tracerall versions
Vulnerabilities

Cisco Packet Tracer

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2010-3135
Untrusted search path vulnerability in Cisco Packet Tracer 5.2 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse wintab32.dll that is located in the same folder as a .pkt or .pkz file.
Published 2010-08-26 · Modified
9.31 PoCEPSS 0.082
CVE-2021-1593
Cisco Packet Tracer for Windows DLL Injection Vulnerability
Published 2021-08-04 · Modified
7.3EPSS 0.003
CVE-2017-12313
An untrusted search path (aka DLL Preload) vulnerability in the Cisco Network Academy Packet Tracer software could allow an authenticated, local attacker to execute arbitrary code via DLL hijacking if a local user with administrative privileges executes the installer in the current working directory where a crafted DLL has been placed by an attacker. The vulnerability is due to incomplete input validation of path and file names of a DLL file before it is loaded. An attacker could exploit this vulnerability by creating a malicious DLL file and installing it in a specific system directory. A successful exploit could allow the attacker to execute commands on the underlying Microsoft Windows host with privileges equivalent to the SYSTEM account. An attacker would need valid user credentials to exploit this vulnerability.
Published 2017-11-16 · Modified
7.2EPSS 0.005