CyberRota Analysis
AI-GeneratedFirmaCheck for Windows prior to version 1.3.16 is vulnerable to a DLL hijacking flaw that enables local attackers to execute arbitrary code by placing a malicious openssl.cnf file in the unvalidated SSL directory. This vulnerability allows for code execution with elevated privileges during the automatic startup of FirmaCheck.exe. Organizations using this software should prioritize patching to mitigate the risk of local exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
FirmaCheck for Windows before 1.3.16 contains a DLL hijacking vulnerability that allows local attackers to execute arbitrary code by placing a crafted openssl.cnf file in the unvalidated C:\Program Files (x86)\Common Files\SSL\ directory path. Attackers can write a malicious OpenSSL configuration file referencing an attacker-controlled DLL to achieve code execution at startup process privilege level when FirmaCheck.exe runs automatically at system startup.