logo

Rattler:Identifying and Exploiting DLL Preloading Vulnerabilities

ID: a2b93319-4892-5cfe-a5a3-e49cd0a4be88

STIX ID: report--a2b93319-4892-5cfe-a5a3-e49cd0a4be88

Feed Name: SensePost Blog

Threat Score
60/100

Date Published: 2016-12-01

Date Updated: 2026-04-29

...
...

Rattler is an automated tool for discovering and attempting to exploit DLL preloading (DLL search order) vulnerabilities in Windows applications. The post describes Rattler's methodology—identifying DLLs loaded without fully qualified paths, placing malicious DLLs in target directories, and executing the application to confirm exploitation—and discusses impacts (persistence, privilege escalation, and possible RCE), remediation (use fully qualified paths), and potential enhancements to the tool.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.