CVE-2018-6318
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
In Sophos Tester Tool 3.2.0.7 Beta, the driver loads (in the context of the application used to test an exploit or ransomware) the DLL using a payload that runs from NTDLL.DLL (so, it's run in userland), but the driver doesn't perform any validation of this DLL (not its signature, not its hash, etc.). A person can change this DLL in a local way, or with a remote connection, to a malicious DLL with the same name -- and when the product is used, this malicious DLL will be loaded, aka a DLL Hijacking attack.
En Sophos Tester Tool 3.2.0.7 Beta, el controlador carga (en el contexto de la aplicación empleada para probar un exploit o ransomware) el DLL mediante una carga útil que se ejecuta desde NTDLL.DLL (por lo que se ejecuta en el espacio de usuario), pero el controlador no realiza ninguna validación de este DLL (ni su firma, ni su hash, etc.). Una persona puede cambiar este DLL de forma local o con una conexión remota a un DLL malicioso con el mismo nombre: cuando se usa el producto, el DLL malicioso se cargará. Esto se conoce como ataque de secuestro de DLL.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-01-26 CVE Reserved
- 2018-02-02 CVE Published
- 2024-08-05 CVE Updated
- 2024-10-15 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-426: Untrusted Search Path
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://29wspy.ru/exploits/CVE-2018-6318.pdf | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Sophos Search vendor "Sophos" | Sophos Tester Search vendor "Sophos" for product "Sophos Tester" | 3.2.0.7 Search vendor "Sophos" for product "Sophos Tester" and version "3.2.0.7" | beta |
Affected
|