Sunday, 23 February 2025
28.8 C
Singapore
35.4 C
Thailand
21.9 C
Indonesia
26.7 C
Philippines

In brief: Report shows close to 300 Windows 10 executables vulnerable to DLL hijacking

  • In a new report from a PwC UK security researcherย Wietze Beukema, it shows that almost 300 Windows 10 executables are vulnerable to DLL hijacking.
  • A simple VBScript may be enough to allow users to gain administrative access and bypass UAC entirelyย on Windows 10.
  • “It turns out nearly 300 executables in your System32 folder are vulnerable to relative path DLL Hijacking. Did you know that with a simple VBScript some of these EXEs can be used to elevate such executions, bypassing UAC entirely?” noted Beukema.
  • The vulnerability referred to here is relative path DLL hijacking, which is when an attacker can cause a legitimate Windows executable to load an arbitrary DLL of the attacker’s choice, most likely with malicious intent.
  • DLL hijacking attacks can prove useful to a skilled attacker as they grant capabilities such as arbitrary code execution, privilege escalation, and persistence on the target system.
  • The various techniques of DLL hijacking covered by theย Beukema’sย blog postย includeย DLL replacement, DLL Proxying, DLL search order hijacking, Phantom DLL hijacking, DLL redirection, WinSxS DLL replacement, and relative path DLL Hijacking.
  • Beukema suggests a few prevention methods that can be used to deter such attacks, such as looking for activity in the mock windows \ folder, should one be present on your machine.
  • Also, adjusting UAC settings to “always notify” could help prevent attacks like this, should the end-user be savvy enough to understand what is about to be executed.
  • Another strategy is monitoring instances of DLL creation and loading from unexpected file paths:
  • When building applications, developers should enforce using absolute and not relative paths for loading DLLs, among several other techniques.
  • None of these may alone be sufficiently foolproof. However, when appropriately applied in conjunction, preventative measures such as those explained by the researcher can deter DLL hijacking attacks by a long shot.

Hot this week

88% of top Asia Pacific companies still vulnerable to email fraud amid rising cyber threats

88% of top Asia Pacific companies lack strong email security, exposing customers to cyber threats as phishing attacks surge. Experts urge action.

Elon Muskโ€™s xAI unveils Grok 3, its most advanced AI model yet

xAI, Elon Muskโ€™s AI company, has launched Grok 3, its latest AI model. It features improved reasoning, new research tools, and expanded subscription plans.

ASUS launches ZenScreen Duo OLED MQ149CD, a portable monitor with dual OLED displays

ASUS unveils the ZenScreen Duo OLED MQ149CD, a portable dual-screen monitor with OLED technology, delivering stunning visuals and flexible work setups.

SBF supports Budget 2025’s focus on long-term growth and cost relief

SBF welcomes Budget 2025โ€™s focus on business transformation, tax relief, and workforce support, reinforcing Singaporeโ€™s long-term economic strategy.

Amazon to shut down its Android app store in August

Amazon will shut down its Android app store on August 20, 2025, and discontinue the Amazon Coins program, with refunds for unused coins.

BT and Equinix expand partnership to enhance global interconnectivity

BT and Equinix expand their partnership to boost interconnectivity for multinational businesses, deploying BTโ€™s Global Fabric NaaS in 40+ Equinix data centres worldwide.

LG unveils new SKS branding for luxury kitchen suite at KBIS 2025

LG rebrands Signature Kitchen Suite to SKS at KBIS 2025, introducing new luxury appliances like a free-zone induction range and an advanced island system.

LG unveils advanced laundry solutions at KBIS 2025

LG unveils its latest heat pump washer and dryer lineup at KBIS 2025, featuring AI-driven efficiency, ventless design, and smart connectivity.

The Vision Pro is now easier to share, and getting a new iPhone app

Appleโ€™s Vision 2.4 update makes sharing the Vision Pro easier, introduces a new iPhone app for content discovery, and adds the Spatial Gallery app.

Related Articles