Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-44939: WindowsPrivilegeEscalation/Research.txt at main · RashidKhanPathan/WindowsPrivilegeEscalation

Efs Software Easy Chat Server Version 3.1 was discovered to contain a DLL hijacking vulnerability via the component TextShaping.dll. This vulnerability allows attackers to execute arbitrary code via a crafted DLL.

CVE
#vulnerability#mac#windows#google

Permalink

Cannot retrieve contributors at this time

> [Suggested description]

> Efs Software Easy Chat Server Version 3.1 was discovered to contain a

> DLL hijacking vulnerability via the component TextShaping.dll. This

> vulnerability allows attackers to execute arbitrary code via a crafted

> DLL.

>

> ------------------------------------------

>

> [Additional Information]

> Proof Of Concept: https://drive.google.com/file/d/1MuIEcuU4paZyS8o2MjAi4tLEKvoFu2ra/view?usp=sharing

> Vendor HomePage Link: https://www.echatserver.com/

> Software Link: https://www.echatserver.com/ecssetup.exe

>

> ------------------------------------------

>

> [VulnerabilityType Other]

> DLL Hijacking

>

> ------------------------------------------

>

> [Vendor of Product]

> Efs Software

>

> ------------------------------------------

>

> [Affected Product Code Base]

> Easy Chat Server - 3.1

>

> ------------------------------------------

>

> [Affected Component]

> TextShaping.dll

>

> ------------------------------------------

>

> [Attack Type]

> Local

>

> ------------------------------------------

>

> [Impact Code execution]

> true

>

> ------------------------------------------

>

> [Attack Vectors]

> TextShaping.dll is missing from Installed path of Easy Chat Server so an attacker can craft malicious dll with same name and can execute arbitrary code on system or also perform way of persistence on victim machine

>

> ------------------------------------------

>

> [Reference]

> https://drive.google.com/file/d/1MuIEcuU4paZyS8o2MjAi4tLEKvoFu2ra/view?usp=sharing

> https://www.echatserver.com/

> https://www.echatserver.com/ecssetup.exe

>

> ------------------------------------------

>

> [Discoverer]

> RashidKhan Pathan

Use CVE-2022-44939

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda