vendor:
eSpace
by:
Gjoko 'LiquidWorm' Krstic
7.8
CVSS
HIGH
DLL Hijacking
427
CWE
Product Name: eSpace
Affected Version From: eSpace 1.1.11.103
Affected Version To: eSpace 1.1.11.103
Patch Exists: YES
Related CWE: CVE-2014-9416
CPE: a:huawei:espace
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Microsoft Windows 7 Professional
2014
Huawei eSpace Desktop DLL Hijacking Vulnerability
eSpace suffers from a DLL Hijacking issue. The vulnerability is caused due to the application loading libraries (mfc71enu.dll, mfc71loc.dll, tcapi.dll and airpcap.dll) in an insecure manner. This can be exploited to load arbitrary libraries by tricking a user into opening a related application file (.html, .jpg, .png) located on a remote WebDAV or SMB share.
Mitigation:
Upgrade to the latest version of eSpace (V200R003C00) to mitigate this vulnerability.