New Variant of DLL Search Order Hijacking Bypasses Windows 10 and 11 Protections
ID: e955bd5d-c061-5f73-8b06-d5f18d787795
STIX ID: report--e955bd5d-c061-5f73-8b06-d5f18d787795
Feed Name: The Hacker News
Security researchers reported a novel DLL search-order hijacking technique that abuses legitimate executables in the Windows WinSxS component (e.g., ngentask.exe, aspnet_wp.exe) to load attacker-controlled DLLs and achieve code execution without elevated privileges. The approach leverages the standard Windows DLL search order by running vulnerable WinSxS binaries from a working directory containing malicious DLLs, enabling defense evasion and persistence; researchers recommend monitoring process parent-child relationships and activities of binaries in the WinSxS folder.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
