Menu

#2182 SECURITY: 2.14.0 Installer vulnerable to DLL Hijacking

Trunk
closed-fixed
security (1)
3
2018-02-25
2016-03-29
No

The WinMerge 2.14.0 installer is vulnerable to a DLL hijacking attack of dwmapi.dll, allowing attacker-supplied code to run in the elevated context of the WinMerge installer.

https://textplain.wordpress.com/2015/12/18/dll-hijacking-just-wont-die/

Discussion

  • Takashi Sawanaka

    • status: open --> closed-fixed
    • assigned_to: Takashi Sawanaka
     
  • Takashi Sawanaka

    I think the problem was fixed in 2.15.2 installer which was created by latest inno setup

     

Log in to post a comment.