A binary hijack in Embarcadero Dev-CPP v6.3 allows attackers to execute arbitrary code via a crafted .exe file.
The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.
Link | Tags |
---|---|
https://github.com/ycdxsb/Vuln/blob/main/Embarcadero-Dev-Cpp-CreateProcessW-Misuse-Binary-Hijack/Embarcadero-Dev-Cpp-CreateProcessW-Misuse-Binary-Hijack.md | third party advisory exploit |