Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Vulnerability type: DLL Hijacking
- Vendor of the product: MindManager
- Product: MindManager Windows
- Version: MindManager versions prior to 25.0.208
- Has the vendor confirmed or acknowledged the vulnerability: Yes
- Attack type: Local
- Impact: Code Execution as Current User
- Affected Components: N/A
- Attack Vectors: To exploit the issue, the attacker must already be able to create or modify DLL files within the victim's DLL search path.
- Suggested Description: In MindManager Windows versions prior to 25.0.208, attackers could potentially gain code execution as other local users on the same machine if they could write DLL files within victims' DLL search paths.
- Discoverer/Credits: Ianis Bernard from NATO Cyber Security Centre (NCSC)
Advertisement
Add Comment
Please, Sign In to add comment