Lucene search

K
packetstormMatei JosephsPACKETSTORM:173990
HistoryAug 04, 2023 - 12:00 a.m.

Diebold Nixdorf Vynamic View Console 5.3.1 DLL Hijacking

2023-08-0400:00:00
Matei Josephs
packetstormsecurity.com
159
diebold nixdorf
vynamic view console
banking software
arbitrary code execution
dll hijacking
security vulnerability
cve-2023-36344
exploit.

0.0005 Low

EPSS

Percentile

16.0%

`# Exploit Title: DLL Hijacking in Diebold Nixdorf Vynamic View Console 5.3.1 Banking Software  
# Date: 2023-08-04  
# Exploit Author: Matei Josephs  
# Vendor Homepage:[https://www.dieboldnixdorf.com/](https://www.dieboldnixdorf.com/en-us/banking/portfolio/software/view/)  
# Version: Diebold Nixdorf Vynamic View Console 5.3.1  
# CVE : CVE-2023-36344  
  
Introduction  
=================  
An issue in Diebold Nixdorf Vynamic View Console v.5.3.1 and before allows a local attacker to execute arbitrary code via not restricting the search path for required DLLs and not verifying the signature. The following DLLs allow DLL Hijcaking:  
VERSION.DLL  
WINMM.DLL  
WSOCK32.DLL  
MSVCR100.DLL  
WINMMBASE.DLL  
USERENV.DLL  
CRYPTBASE.DLL  
URLMON.DLL  
IEUTIL.DLL  
SRVCLI.DLL  
NETUTILS.DLL  
IPHLPAPI.DLL  
USP10.DLLWININET.DLL  
  
Proof of Concept  
=================  
An attacker can create a malicious DLL, rename it to one of the above and place it in the folder where the executable attempts to load the DLL. When the program is executed, the malicious DLL runs in the context of the benign program.  
  
Kind regards,Matei  
`

0.0005 Low

EPSS

Percentile

16.0%

Related for PACKETSTORM:173990