Advertisement






Efficient Calendar dll hijacking

CVE Category Price Severity
CVE-2020-16692 CWE-426 $3,000 High
Author Risk Exploitation Type Date
Mohammed Alfateh High Local 2018-03-22
CPE
cpe:cpe:/a:efficient:calendar
CVSS EPSS EPSSP
CVSS:4.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 0.01777 0.56651

CVSS vector description

Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2018030184

Below is a copy:

Efficient Calendar dll hijacking
##########################
# Exploit Title: Efficient Calendar DLL hijacking Vulnerability
# Software Link: http://www.efficientdownload.com/es/EfficientCalendarNetwork-Setup.exe
# Version: 5.50
# Vendor Homepage : http://www.efficientsoftware.net/
# Tested on : windows
# Exploit Author: Iran Security Group
##########################
+--------------------------+
+ Vulnerable DLL :
+ gds32.dll
+--------------------------+
product:
+-------+
Efficient Calendar Network is designed for SME to share data.
 The network edition has all features of pro version, such as, to-do lists, calendar reminder, group management, one-touch search, etc..
 Besides, with network edition, different users in organization can access the same copy of data, to work in conjunction and improve work efficiency!
+-------+
Impact:
+-------+
Attacker can exploit the vulnerability to load a DLL file of the attacker's
choosing that could execute arbitrary code. This may help attacker to
Successful exploits the system if user creates shell as a DLL.
Make Malicious dll.
+-------+

Exploit:
Place a dummy gds32.dll file with the malicious dll . When the file is opened you will get shell.


###################################
# Iran Security Group - iran-sec.net
# Discovered By: Mr.voltage
# [email protected]
###################################

Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum