PT-2018-2885 · Блокхост · Blockhost
Published
2018-12-20
·
Updated
2018-12-20
CVSS v2.0
6.8
Medium
| Vector | AV:L/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Блокхост – сеть К (affected versions not specified)
Description
The issue is related to the lack of integrity checks for loaded libraries. An attacker, acting locally, can exploit this to execute arbitrary code with ntauthority/system privileges by placing substitute dll-libraries in the application directory C:BlockHostSystem32, which will be loaded instead of system libraries when the application starts.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Untrusted Search Path
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Blockhost