Huawei Mobile Partner 'wintab32.dll' DLL Loading Arbitrary Code Execution Vulnerability
BID:70671
Info
Huawei Mobile Partner 'wintab32.dll' DLL Loading Arbitrary Code Execution Vulnerability
| Bugtraq ID: | 70671 |
| Class: | Design Error |
| CVE: |
CVE-2014-8359 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 20 2014 12:00AM |
| Updated: | Mar 19 2015 08:38AM |
| Credit: | Osanda Malith |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Huawei Mobile Partner 'wintab32.dll' DLL Loading Arbitrary Code Execution Vulnerability
Huawei Mobile Partner is prone to a vulnerability that lets attackers execute arbitrary code.
Attackers can exploit this issue by enticing a legitimate user to use the vulnerable application to open a file from a network share location that contains a specially crafted Dynamic Link Library (DLL) file.
Attackers can exploit this vulnerability to execute arbitrary code in the context of the user running the vulnerable application.
Huawei Mobile Partner 23.009.05.03.1014 is vulnerable; other versions may also be affected.
Huawei Mobile Partner is prone to a vulnerability that lets attackers execute arbitrary code.
Attackers can exploit this issue by enticing a legitimate user to use the vulnerable application to open a file from a network share location that contains a specially crafted Dynamic Link Library (DLL) file.
Attackers can exploit this vulnerability to execute arbitrary code in the context of the user running the vulnerable application.
Huawei Mobile Partner 23.009.05.03.1014 is vulnerable; other versions may also be affected.
Solution / Fix
Huawei Mobile Partner 'wintab32.dll' DLL Loading Arbitrary Code Execution Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Huawei Mobile Partner 'wintab32.dll' DLL Loading Arbitrary Code Execution Vulnerability
References:
References:
- Application DLL Load Hijacking (HD Moore)
- Download Mobile Partner Latest Version (Huawei)
- Escalating Local Privileges Using Mobile Partner (Osanda Malith)
- Exploiting DLL Hijacking Flaws (hdm)
- Huawei Home Page (Huawei Technologies)
- Microsoft Security Advisory 2269637 Released (Microsoft)
- More information about the DLL Preloading remote attack vector (Microsoft)
- New DLL Hijacking Exploits (many!) (Matt)
- Microsoft Security Advisory (2269637) (Microsoft)
- Security Advisory-DLL Hijacking Vulnerability on Huawei USB Modem products (Huawei Technologies)