PT-2018-2885 · Блокхост · Blockhost
Publicado
2018-12-20
·
Atualizado
2018-12-20
CVSS v2.0
6.8
Média
| Vetor | AV:L/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Блокхост – сеть К (affected versions not specified)
Description
The issue is related to the lack of integrity checks for loaded libraries. An attacker, acting locally, can exploit this to execute arbitrary code with ntauthority/system privileges by placing substitute dll-libraries in the application directory C:BlockHostSystem32, which will be loaded instead of system libraries when the application starts.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Untrusted Search Path
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Blockhost