Lenovo Bluetooth with Enhanced Data Rate Software DLL Loading Arbitrary Code Execution Vulnerability
BID:57504
Info
Lenovo Bluetooth with Enhanced Data Rate Software DLL Loading Arbitrary Code Execution Vulnerability
| Bugtraq ID: | 57504 |
| Class: | Design Error |
| CVE: |
CVE-2013-1361 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 22 2013 12:00AM |
| Updated: | Jan 22 2013 12:00AM |
| Credit: | Haifei Li of Microsoft |
| Vulnerable: |
Lenovo Bluetooth with Enhanced Data Rate Software 6.4.0.2900 |
| Not Vulnerable: |
Lenovo Bluetooth with Enhanced Data Rate Software 6.5.1.2700 |
Exploit / POC
Lenovo Bluetooth with Enhanced Data Rate Software DLL Loading Arbitrary Code Execution Vulnerability
A general exploit technique has been documented by TheLeader and H.D. Moore for the Metasploit Project; please see the references for more information.
A general exploit technique has been documented by TheLeader and H.D. Moore for the Metasploit Project; please see the references for more information.
Solution / Fix
Lenovo Bluetooth with Enhanced Data Rate Software DLL Loading Arbitrary Code Execution Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Lenovo Bluetooth with Enhanced Data Rate Software DLL Loading Arbitrary Code Execution Vulnerability
References:
References:
- Application DLL Load Hijacking (HD Moore)
- More information about the DLL Preloading remote attack vector (Microsoft)
- New DLL Hijacking Exploits (many!) (Matt)
- Microsoft Security Advisory (2269637) (Microsoft)