vendor:
Windows
by:
Tyler Borland
7.5
CVSS
HIGH
Arbitrary Code Execution
CWE
Product Name: Windows
Affected Version From: Windows Vista/7
Affected Version To: Windows Vista/7
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows Vista/7
2010
Windows Vista/7 lpksetup.exe (oci.dll) DLL Hijacking Vulnerability
Microsoft Windows 'lpksetup.exe' is prone to a vulnerability that lets attackers execute arbitrary code. An attacker can exploit this issue by enticing a legitimate user to use the vulnerable application to open a file from a network share location that contains a specially crafted Dynamic Link Library (DLL) file.