CVE-2017-12580 Information
Description
An issue was discovered in IDM UltraEdit through 24.10.0.32. To exploit the vulnerability on unpatched Windows systems an attacker could include in the same directory as the affected executable a DLL using the name of a Windows DLL. This DLL must be preloaded by the executable (for example \ntmarta.dll). When the installer EXE is executed by the user the DLL located in the EXE’s current directory will be loaded instead of the Windows DLL allowing the attacker to run arbitrary code on the affected system.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Reference
https://support.microsoft.com/en-us/help/2389418/secure-loading-of-libraries-to-prevent-dll-preloading-attacks https://www.fortiguard.com/zeroday/FG-VD-17-089
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
7.8
Share on: