Insecure DLL loading in Ghost Solution Suite - CVE-2018-18364
Published: February 18, 2019
Vulnerability details
The vulnerability allows an adjacent authenticated attacker to compromise vulnerable system.
The vulnerability exists due to the application loads DLL libraries in an insecure manner. A remote attacker can place a specially crafted .dll file on a remote SMB fileshare, trick the victim into opening a file, associated with the vulnerable application, and execute arbitrary code on victim's system.