The most popular Windows software vulnerable to attacks that exploit a security bug in the DLL application: among the programs at risk are the popular Firefox, Chrome, Safari, Opera, Microsoft Word 2007, Adobe Photoshop, Skype, uTorrent, and many others (those over 40 are all on the list).
“Incredibly fast pace of the release of exploits that target vulnerabilities in the Windows software,” reads the alarm raised by Andrew Storms, director of security operations for nCircle Security.
Called by some DLL load hijacking, binary planting by others, this type of security exploit is mobilizing the software company and Microsoft‘s own antivirus and antimalware to hurry up and release of security bulletins that they can avoid risks to users’ computers.
In the meantime, Microsoft has published a guide to avoid many of these known attacks
The problem stems from how many applications for Windows DLL’s recall: the cracker could exploit this vulnerability by calling DLLs with malicious code, but with the same name as DLL needed for the proper functioning of the application and system.
Even before Microsoft, the problem was noticed HD Moore, creator of the Metasploit hacking toolkit open-source, which issued a
monitoring tools of the possible security bug of DLLs which have spread through the lists of applications, potentially, on which the developers have clearly begun to put his hand immediately.
Many people wait for a security patch from Microsoft, which as Moore says, will be difficult, since vulnerabilities affecting applications developed by third parties and not by Microsoft.
Evolve as the situation is difficult to predict, since the exploits are for now only been highlighted by security companies, although it is likely that they can quickly be used by crackers to infect users’ computers.
Everything you need to do is wait for further developments, it is highly likely that there will be relatively quickly, even if a solution to the problem will most likely only in several months, as confirmed by Moore.