PT-2012-5618 · Unknown · Xtreme Rat
Published
2012-09-06
·
Updated
2017-08-29
·
CVE-2012-4866
CVSS v2.0
6.9
Medium
| Vector | AV:L/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Xtreme RAT version 3.5
Description
The issue allows local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll located in the same folder as the current working directory.
Recommendations
For Xtreme RAT version 3.5, consider restricting access to the current working directory to minimize the risk of exploitation, and avoid using untrusted search paths until a fix is available.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Xtreme Rat