vendor:
Winamp
by:
Gjoko 'LiquidWorm' Krstic
7,2
CVSS
HIGH
DLL Hijacking
427
CWE
Product Name: Winamp
Affected Version From: 5.581 (x86)
Affected Version To: 5.581 (x86)
Patch Exists: Yes
Related CWE: N/A
CPE: a:nullsoft:winamp:5.581
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Microsoft Windows XP Professional SP3 (EN)
2010
Nullsoft Winamp 5.581 (wnaspi32.dll) DLL Hijacking Exploit
Winamp 5.581 suffers from a dll hijacking vulnerability that enables the attacker to execute arbitrary code on a local level. The vulnerable extensions are .669, .aac, .aiff, .amf, .au, .avr, .b4s, .caf and .cda thru wnaspi32.dll and dwmapi.dll libraries.
Mitigation:
Ensure that the application is not vulnerable to DLL hijacking by using the latest version of the application.