70273vdb entry
http://osvdb.org/70273 CVE-2011-0403
ImgBurn 2.4 - 'dwmapi.dll' DLL Loading Arbitrary Code Execution
Record summary
CVE-2011-0403 has a selected CVSS score of 9.3; EIP currently links 1 catalogued exploit.
Description
Untrusted search path vulnerability in ImgBurn.exe in ImgBurn 2.4.0.0, 2.5.4.0, and other versions allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the same folder as a CUE file.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBImgBurn 2.4 - 'dwmapi.dll' DLL Loading Arbitrary Code ExecutionExploitDB exploitby d3c0derNot analyzed1 file
References
6packetstormsecurity.org
http://packetstormsecurity.org/files/view/97207/imgburn-dllhijack.txt 42798Third-party advisory
http://secunia.com/advisories/42798 45657vdb entry
http://www.securityfocus.com/bid/45657 imgburn-dll-code-execution(64478)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/64478 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2011-0403