e-Tax software CVE-2017-2226 DLL Loading Remote Code Execution Vulnerability



Installer of Setup file of advance preparation for e-Tax software (WEB version) is prone to a remote code-execution vulnerability.

An attacker can leverage this issue to execute arbitrary code in the context of the currently logged-in user. Failed exploit attempts will likely result in denial-of-service conditions.

Installer of Setup file of advance preparation for e-Tax software (WEB version) 1.17.0 is vulnerable; other versions may also be affected.

Information

Bugtraq ID: 99334
Class: Unknown
CVE: CVE-2017-2226

Remote: Yes
Local: No
Published: Jun 29 2017 12:00AM
Updated: Jun 29 2017 12:00AM
Credit: BlackWingCat of Pink Flying Whale
Vulnerable: LINK Setup file of advance preparation for e-Tax software 1.17


Not Vulnerable: LINK Setup file of advance preparation for e-Tax software 1.17.1


Exploit


A general exploit technique has been documented by TheLeader and H.D. Moore for the Metasploit Project; please see the references for more information.


Related Posts