LINDO Systems LINGO Multiple Insecure Library Loading Arbitrary Code Execution Vulnerabilities
BID:43512
Info
LINDO Systems LINGO Multiple Insecure Library Loading Arbitrary Code Execution Vulnerabilities
| Bugtraq ID: | 43512 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 27 2010 12:00AM |
| Updated: | Dec 28 2010 06:13PM |
| Credit: | APA-IUTcert Vulnerability Analysis Team |
| Vulnerable: |
LINDO Systems LINGO 12.0.2.20 LINDO Systems LINGO 11.0.1.6 |
| Not Vulnerable: |
LINDO Systems LINGO 12.0.3.27 LINDO Systems LINGO 11.0.1.9 |
Discussion
LINDO Systems LINGO Multiple Insecure Library Loading Arbitrary Code Execution Vulnerabilities
LINDO Systems LINGO is prone to multiple vulnerabilities that lets attackers execute arbitrary code.
An attacker can exploit these issues by placing a malicious library file in the installation directory or enticing a legitimate user to use the vulnerable application to open a file from a network share location that contains a specially crafted Dynamic Link Library (DLL) file.
LINGO 11.0.1.6 and 12.0.2.20 are vulnerable; other versions may also be affected.
LINDO Systems LINGO is prone to multiple vulnerabilities that lets attackers execute arbitrary code.
An attacker can exploit these issues by placing a malicious library file in the installation directory or enticing a legitimate user to use the vulnerable application to open a file from a network share location that contains a specially crafted Dynamic Link Library (DLL) file.
LINGO 11.0.1.6 and 12.0.2.20 are vulnerable; other versions may also be affected.
Exploit / POC
LINDO Systems LINGO Multiple Insecure Library Loading Arbitrary Code Execution Vulnerabilities
Attackers can exploit these issues by placing a malicious library file in the installation directory or by tricking a user into opening a file on a remote WebDAV or SMB share.
Attackers can exploit these issues by placing a malicious library file in the installation directory or by tricking a user into opening a file on a remote WebDAV or SMB share.
Solution / Fix
LINDO Systems LINGO Multiple Insecure Library Loading Arbitrary Code Execution Vulnerabilities
Solution:
Updates are available; please contact the vendor for more information.
Solution:
Updates are available; please contact the vendor for more information.
References
LINDO Systems LINGO Multiple Insecure Library Loading Arbitrary Code Execution Vulnerabilities
References:
References:
- Application DLL Load Hijacking (HD Moore)
- Exploiting DLL Hijacking Flaws (hdm)
- LINGO Homepage (LINDO Systems)
- Microsoft Security Advisory 2269637 Released (Microsoft)
- More information about the DLL Preloading remote attack vector (Microsoft)
- Microsoft Security Advisory (2269637) (Microsoft)