Vault7: CIA Hacking Tools Revealed
Navigation: » Latest version
Owner: User #71468
LibreOffice Portable DLL Hijack
Procmon screenshot of some vulnerable DLLDynamic Link Library loads:
Out of these, I tested both "MSIMG32.dll" and "dbgcore.dll" and both were successful
Althogh we have the prototypes of all exported functions of both these lbiraries, I'd recommend using the dbgcore.dll as it appears to be unloaded as soon as it is loaded. In contrast, msimg32 stays loaded for the lenght of the process' life. The "program" directory is a great place to store files as there are serveral DLLs occuring naturally
TL;DR: use dbgcore.dll in \app\libreoffice\program