vendor:
Office
by:
Google Security Research
7,8
CVSS
HIGH
DLL Planting Attack
427
CWE
Product Name: Office
Affected Version From: Microsoft Office 2010
Affected Version To: Microsoft Office 2013
Patch Exists: YES
Related CWE: N/A
CPE: a:microsoft:office:2010
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7 x86, Windows 7 x64
2014
DLL Planting Attack in Microsoft Office 2010
It is possible for an attacker to execute a DLL planting attack in Microsoft Office 2010 on Windows 7 x86 with a specially crafted OLE object. This attack also works on Office 2013 running on Windows 7 x64. When a user opens this document and single clicks on the icon for foo.txt ole32!OleLoad is invoked on our vulnerable CLSID. This results in a call to a class factory constructor that tries eventually tries to call mqrt!MQGetPrivateComputerInformation. Because mqrt is a delay loaded dll the loader has inserted a stub to call _tailMerge_mqrt_dll on the first call of this function. This results in a kernelbase!LoadLibraryExA call vulnerable to dll planting.
Mitigation:
Ensure that all applications are up to date and patched with the latest security updates.