Nitro PDF Multiple DLL Loading Arbitrary Code Execution Vulnerabilities
BID:43199
Info
Nitro PDF Multiple DLL Loading Arbitrary Code Execution Vulnerabilities
| Bugtraq ID: | 43199 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 13 2010 12:00AM |
| Updated: | Sep 13 2010 12:00AM |
| Credit: | Aung Khant |
| Vulnerable: |
Nitro PDF Nitro PDF 2.5.1 |
| Not Vulnerable: | |
Discussion
Nitro PDF Multiple DLL Loading Arbitrary Code Execution Vulnerabilities
Nitro PDF is prone to multiple vulnerabilities that let attackers execute arbitrary code.
An attacker can exploit these issues by enticing a legitimate user to use the vulnerable application to open a file from a network share location that contains a specially crafted Dynamic Link Library (DLL) file.
Nitro PDF 2.5.1 is vulnerable; other versions may also be affected.
Nitro PDF is prone to multiple vulnerabilities that let attackers execute arbitrary code.
An attacker can exploit these issues by enticing a legitimate user to use the vulnerable application to open a file from a network share location that contains a specially crafted Dynamic Link Library (DLL) file.
Nitro PDF 2.5.1 is vulnerable; other versions may also be affected.
Exploit / POC
Nitro PDF Multiple DLL Loading Arbitrary Code Execution Vulnerabilities
A general exploit technique has been documented by TheLeader and H.D. Moore for the Metasploit Project; please see the references for more information.
A general exploit technique has been documented by TheLeader and H.D. Moore for the Metasploit Project; please see the references for more information.
Solution / Fix
Nitro PDF Multiple DLL Loading Arbitrary Code Execution Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Nitro PDF Multiple DLL Loading Arbitrary Code Execution Vulnerabilities
References:
References:
- Application DLL Load Hijacking (HD Moore)
- Exploiting DLL Hijacking Flaws (hdm)
- Microsoft Security Advisory 2269637 Released (Microsoft)
- Microsoft Windows Homepage (Microsoft)
- More information about the DLL Preloading remote attack vector (Microsoft)
- Nitro PDF - Homepage (Nitro PDF)
- Microsoft Security Advisory (2269637) (Microsoft)