logo

New Variant of DLL Search Order Hijacking Bypasses Windows 10 and 11 Protections

ID: e955bd5d-c061-5f73-8b06-d5f18d787795

STIX ID: report--e955bd5d-c061-5f73-8b06-d5f18d787795

Feed Name: The Hacker News

Threat Score
60/100

Date Published: 2024-01-01

Date Updated: 2026-04-23

Author: [email protected] (The Hacker News)

...
...

Security researchers reported a novel DLL search-order hijacking technique that abuses legitimate executables in the Windows WinSxS component (e.g., ngentask.exe, aspnet_wp.exe) to load attacker-controlled DLLs and achieve code execution without elevated privileges. The approach leverages the standard Windows DLL search order by running vulnerable WinSxS binaries from a working directory containing malicious DLLs, enabling defense evasion and persistence; researchers recommend monitoring process parent-child relationships and activities of binaries in the WinSxS folder.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.