Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.801399
Category:Windows
Title:Microsoft Windows Insecure Library Loading Remote Code Execution Vulnerabilities (2269637)
Summary:This host is prone to Remote Code Execution vulnerabilities.
Description:Summary:
This host is prone to Remote Code Execution vulnerabilities.

Vulnerability Insight:
The flaws are due to:

- An error in the loading of dynamic link libraries (DLLs). If an application
does not securely load DLL files, an attacker may be able to cause the
application to load an arbitrary library.

- A specific insecure programming practices that allow so-called
'binary planting' or 'DLL preloading attacks', which allows the attacker to
execute arbitrary code in the context of the user running the vulnerable
application when the user opens a file from an untrusted location.

Vulnerability Impact:
Successful exploitation will allow attackers to execute arbitrary code or to
elevate privileges.

Affected Software/OS:
- Microsoft Windows 7

- Microsoft Windows XP Service Pack 3 and prior

- Microsoft Windows 2003 Service Pack 2 and prior

- Microsoft Windows Vista Service Pack 2 and prior

- Microsoft Windows Server 2008 Service Pack 2 and prior

Solution:
The vendor has released updates. Please see the references for more information.

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

CopyrightCopyright (C) 2010 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.