An issue in RAONWIZ K Editor v2018.0.0.10 allows attackers to perform a DLL hijacking attack when the service or system is restarted.
The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.
Link | Tags |
---|---|
https://gist.github.com/blackcon/ae155656d21a2228aa25fdcb79c85159 | third party advisory exploit |
https://docs.microsoft.com/en-us/windows/win32/dlls/dynamic-link-library-search-order | third party advisory |