vendor:
BS.Player
by:
Bruno Filipe
7,8
CVSS
HIGH
DLL Hijacking
427
CWE
Product Name: BS.Player
Affected Version From: <= 2.56 build 1043
Affected Version To: <= 2.56 build 1043
Patch Exists: NO
Related CWE: N/A
CPE: a:bsplayer:bs.player
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: WinXP SP2, WinXP SP3
2010
BS.Player DLL Hijacking Exploit (mfc71loc.dll)
This exploit allows an attacker to execute arbitrary code on a vulnerable system by hijacking a DLL file associated with BS.Player. The attacker can create a malicious DLL file and place it in the same directory as a media file handled by BS.Player. When the media file is opened, the malicious DLL will be executed.
Mitigation:
Ensure that all DLL files are from trusted sources and are digitally signed.