Vulnerabilities > CVE-2014-1680 - Unspecified vulnerability in Bandisoft Bandizip
Attack vector
LOCAL Attack complexity
MEDIUM Privileges required
NONE Confidentiality impact
COMPLETE Integrity impact
COMPLETE Availability impact
COMPLETE local
bandisoft
Summary
Untrusted search path vulnerability in Bandisoft Bandizip before 3.10 allows local users to gain privileges via a Trojan horse dwmapi.dll file in the current working directory. Per: http://cwe.mitre.org/data/definitions/426.html "CWE-426: Untrusted Search Path"
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 10 |
Packetstorm
data source | https://packetstormsecurity.com/files/download/125059/bandizip-dllhijack.txt |
id | PACKETSTORM:125059 |
last seen | 2016-12-05 |
published | 2014-02-05 |
reporter | Osanda Malith |
source | https://packetstormsecurity.com/files/125059/Bandizip-3.09-DLL-Hijack.html |
title | Bandizip 3.09 DLL Hijack |
Seebug
bulletinFamily | exploit |
description | CVE(CAN) ID: CVE-2014-1680 Bandizip是免费的轻量级Zip压缩软件。 Bandisoft Bandizip 3.10之前版本加载库(例如dwmapi.dll)的方式不安全,攻击者通过诱使用户打开远程WebDAV或SMB共享上的文件,利用此漏洞可加载任意库。 0 bandisoft Bandizip 3.08 厂商补丁: bandisoft --------- 目前厂商已经发布了升级补丁以修复这个安全问题,请到厂商的主页下载: http://www.bandisoft.com/bandizip/history/ |
id | SSV:61474 |
last seen | 2017-11-19 |
modified | 2014-02-19 |
published | 2014-02-19 |
reporter | Root |
source | https://www.seebug.org/vuldb/ssvid-61474 |
title | Bandizip不安全库加载漏洞 |