CVE-2020-9767
HIGHZoom Sharing Service - Uncontrolled Search Path Element via DLL Loading
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-9767. PoCs published by shubham0d.
AI-analyzed exploit summary This repository contains a functional DLL hijacking exploit for Zoom versions prior to 5.1.3, leveraging the absence of `SHCore.dll` on older Windows systems. The exploit involves placing a malicious `SHCore.dll` in Zoom's application directory, which gets loaded and executed when Zoom starts or performs certain actions.
Description
A vulnerability related to Dynamic-link Library (“DLL”) loading in the Zoom Sharing Service would allow an attacker who had local access to a machine on which the service was running with elevated privileges to elevate their system privileges as well through use of a malicious DLL. Zoom addressed this issue, which only applies to Windows users, in the 5.0.4 client release.
Exploits (1)
This repository contains a functional DLL hijacking exploit for Zoom versions prior to 5.1.3, leveraging the absence of `SHCore.dll` on older Windows systems. The exploit involves placing a malicious `SHCore.dll` in Zoom's application directory, which gets loaded and executed when Zoom starts or performs certain actions.
References (1)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H