Back to search
CVE-2018-20211
Published: Jan 2, 2019
Modified: Aug 5, 2024
PUBLISHED
Description
ExifTool 8.32 allows local users to gain privileges by creating a %TEMP%\par-%username%\cache-exiftool-8.32 folder with a victim's username, and then copying a Trojan horse ws32_32.dll file into this new folder, aka DLL Hijacking. NOTE: 8.32 is an obsolete version from 2010 (9.x was released starting in 2012, and 10.x was released starting in 2015).
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
20181221 CVE-2018-20211 - DLL Hijacking in Exiftool v8.3.2.0
mailing-list
x_refsource_FULLDISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now