Menu

#1654 7Zip installer vulnerable to DLL hijacking

open
nobody
security (8)
3
2016-04-03
2016-04-03
No

The 7-zip installer is vulnerable to DLL hijacking attacks, similar to those described here: https://textplain.wordpress.com/2015/12/18/dll-hijacking-just-wont-die/

For instance, a planted trojan DLL named "netutils.dll" is loaded and executed by the installer as it completes running on Windows 10.

2 Attachments

Discussion


Log in to post a comment.