Nero DLL Loading Arbitrary Code Execution Vulnerability
BID:43539
Info
Nero DLL Loading Arbitrary Code Execution Vulnerability
| Bugtraq ID: | 43539 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 28 2010 12:00AM |
| Updated: | Dec 13 2010 03:34PM |
| Credit: | Mister Teatime and Secunia Research |
| Vulnerable: |
Nero Vision 4.9.7 6 Nero SoundTrax 2.10.1 0 Nero ShowTime 3.10.1 0 Nero PhotoSnap Viewer 1.2 25 Nero PhotoSnap 1.2 25 Nero Nero 7.11.10 0 Nero CoverDesigner 2.10.1 1 Nero Burning ROM 7.11.10 0 Nero BackItUp 2.10.6 4 |
| Not Vulnerable: | |
Discussion
Nero DLL Loading Arbitrary Code Execution Vulnerability
Nero is prone to a vulnerability that lets attackers execute arbitrary code.
An attacker can exploit this issue by enticing a legitimate user to use the vulnerable application to open a file from a network share location that contains a specially crafted Dynamic Link Library (DLL) file.
Nero 7.11.10.0 is vulnerable; other versions may also be affected.
Nero is prone to a vulnerability that lets attackers execute arbitrary code.
An attacker can exploit this issue by enticing a legitimate user to use the vulnerable application to open a file from a network share location that contains a specially crafted Dynamic Link Library (DLL) file.
Nero 7.11.10.0 is vulnerable; other versions may also be affected.
Exploit / POC
Nero DLL Loading Arbitrary Code Execution Vulnerability
Attackers must entice an unsuspecting user to open a file on a remote WebDAV or SMB share to exploit this issue.
A general exploit technique has been documented by TheLeader and H.D. Moore for the Metasploit Project; please see the references for more information.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Attackers must entice an unsuspecting user to open a file on a remote WebDAV or SMB share to exploit this issue.
A general exploit technique has been documented by TheLeader and H.D. Moore for the Metasploit Project; please see the references for more information.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
Nero DLL Loading Arbitrary Code Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Nero DLL Loading Arbitrary Code Execution Vulnerability
References:
References:
- Application DLL Load Hijacking (HD Moore)
- Exploiting DLL Hijacking Flaws (hdm)
- Microsoft Security Advisory 2269637 Released (Microsoft)
- More information about the DLL Preloading remote attack vector (Microsoft)
- Nero Homepage (Nero)
- Microsoft Security Advisory (2269637) (Microsoft)