A binary hijack in Orwell-Dev-Cpp v5.11 allows attackers to execute arbitrary code via a crafted .exe file.
The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.
Link | Tags |
---|---|
https://github.com/ycdxsb/Vuln/blob/main/Orwell-Dev-Cpp-CreateProcessA-Misuse-Binary-Hijack/Orwell-Dev-Cpp-CreateProcessA-Misuse-Binary-Hijack.md | third party advisory exploit |