Untrusted search path vulnerability in F-Secure Online Scanner allows remote attackers to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse DLL that is located in the same folder as F-SecureOnlineScanner.exe.
The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/537803/100/0/threaded | mailing list |
https://www.f-secure.com/en/web/labs_global/fsc-2015-4 | vendor advisory |
http://www.securityfocus.com/bid/79657 | vdb entry third party advisory |
http://seclists.org/fulldisclosure/2016/Mar/64 | third party advisory mailing list |