Multiple untrusted search path vulnerabilities in Putty beta 0.67 allow local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse (1) UxTheme.dll or (2) ntmarta.dll file in the current working directory.
The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.
Link | Tags |
---|---|
https://packetstormsecurity.com/files/137742/Putty-Beta-0.67-DLL-Hijacking.html | exploit vdb entry third party advisory |
http://www.securitytracker.com/id/1036236 | vdb entry third party advisory broken link |
http://www.securityfocus.com/archive/1/538848/100/0/threaded | mailing list vdb entry third party advisory broken link |