Save the Environment
Many applications appear to rely on Environment Variables such as %SYSTEMROOT% to load DLLs from protected locations.
By changing these variables on process level, it is possible to let a legitimate program load arbitrary DLLs.
https://github.com/wietze/windows-dll-env-hijacking
Research:
https://www.wietzebeukema.nl/blog/save-the-environment-variables
#maldev #dll #hijacking #environment
@pfk_0day
Post #40
1.1K