Audacity 2.1.2 DLL Hijacking

Tempest Security Intelligence Advisory ADV-7/2016 – Audacity version 2.1.2 is vulnerable to dll hijacking as it tries to load avformat-55.dll without supplying the absolute path, thus relying upon the presence of such dll on the system directory. This behavior results in an exploitable dll hijacking vulnerability, even if the SafeDllSerchMode flag is enabled.

Leave a Reply