vendor:
Microsoft Office
by:
Google Security Research
5.5
CVSS
MEDIUM
DLL planting attack
426
CWE
Product Name: Microsoft Office
Affected Version From: Microsoft Office 2013
Affected Version To: Not mentioned
Patch Exists: YES
Related CWE: Not mentioned
CPE: a:microsoft:office:2013
Platforms Tested: Windows 7 x64 with Office 2013 installed
Not mentioned
DLL Planting Attack in Microsoft Office
It is possible for an attacker to execute a DLL planting attack in Microsoft Office with a specially crafted OLE object. The attached POC document contains an embedded Packager object with a modified CLSID that triggers the vulnerable LoadLibraryW() call, resulting in the loading of a malicious DLL from the current working directory of Word.
Mitigation:
To mitigate this vulnerability, ensure that the Office software is up to date with the latest security patches. Additionally, exercise caution when opening documents from untrusted sources.