February 6, 2025 · Applied Cybernetics Group
CVE-2022-23748 — Audinate Dante Discovery
Dante Discovery Process Control Vulnerability
- Added to KEV
2025-02-06- Federal due date
2025-02-27- Vendor
- Audinate
- Product
- Dante Discovery
- EPSS
- 93.3th percentile (score 0.103, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Unknown
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2022-23748
CISA short description
Dante Discovery contains a process control vulnerability in mDNSResponder.exe that all allows for a DLL sideloading attack. A local attacker can leverage this vulnerability in the Dante Application Library to execute arbitrary code.
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.