vendor:
Windows Live Suite
by:
Nicolas Krassas
7,5
CVSS
HIGH
DLL Hijacking
427
CWE
Product Name: Windows Live Suite
Affected Version From: Latest Windows Live Suite
Affected Version To: Latest Windows Live Suite
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP3
2010
Windows Live Email DLL Hijacking Exploit ( dwmapi.dll )
This exploit is based on the exploit from 'TheLeader' and is used to hijack Windows Live Email DLLs. It is tested on Windows XP SP3 and vulnerable extensions are .eml, .nws and .rss. The code includes a function 'evil()' which executes the Windows calculator when called.
Mitigation:
Ensure that all applications are up-to-date and patched with the latest security updates. Also, ensure that all DLLs are properly signed and verified.