Bandizip 'dwmapi.dll' Insecure Library Loading Arbitrary Code Execution Vulnerability
BID:65452
Info
Bandizip 'dwmapi.dll' Insecure Library Loading Arbitrary Code Execution Vulnerability
| Bugtraq ID: | 65452 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 05 2014 12:00AM |
| Updated: | Feb 05 2014 12:00AM |
| Credit: | Osanda Malith |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Bandizip 'dwmapi.dll' Insecure Library Loading Arbitrary Code Execution Vulnerability
Bandizip is prone to a vulnerability that allow attackers to execute arbitrary code.
Attackers can exploit this vulnerability to execute arbitrary code in the context of the user running the application.
Bandizip 3.08 and 3.09 are vulnerable; other versions may also be affected.
Bandizip is prone to a vulnerability that allow attackers to execute arbitrary code.
Attackers can exploit this vulnerability to execute arbitrary code in the context of the user running the application.
Bandizip 3.08 and 3.09 are vulnerable; other versions may also be affected.
Exploit / POC
Bandizip 'dwmapi.dll' Insecure Library Loading Arbitrary Code Execution Vulnerability
A general exploit technique has been documented by TheLeader and H.D. Moore for the Metasploit Project; please see the references for more information.
A general exploit technique has been documented by TheLeader and H.D. Moore for the Metasploit Project; please see the references for more information.
Solution / Fix
Bandizip 'dwmapi.dll' Insecure Library Loading Arbitrary Code Execution Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Bandizip 'dwmapi.dll' Insecure Library Loading Arbitrary Code Execution Vulnerability
References:
References:
- Application DLL Load Hijacking (HD Moore)
- Exploiting DLL Hijacking Flaws (hdm)
- More information about the DLL Preloading remote attack vector (Microsoft)
- Microsoft Security Advisory (2269637) (Microsoft)