Skip to content

Latest commit

 

History

History
17 lines (9 loc) · 882 Bytes

File metadata and controls

17 lines (9 loc) · 882 Bytes

The name of an affected Product : Genymotion Desktop

CVE ID: CVE-2022-48077

Researcher: Abdullah Khawaja

Vendor HomePage Link: https://www.genymotion.com

Affected Version : 3.3.2

Vulnerability Type : DLL Hijacking

Description : profapi.dll is missing so an attacker can use a malicious dll with same name and can get a admin privileges and also perform a way of persistence on the victim machine.

Impact : An attacker could exploit this vulnerability by placing a malicious DLL file on the targeted system. This file will execute when the vulnerable application launches. A successful exploit could allow the attacker to execute arbitrary code on the targeted system with SYSTEM PRIVILEGES as well the attacker can maintain persistence on the target system.