Discord Untrusted Search Path Vulnerability in profapi.dll

Vulnerability

A vulnerability allowing code injection through an untrusted search path in the profapi.dll library has been identified in Discord versions prior to 1.0.9177 on Windows. This vulnerability arises because the application loads DLL files from a local installation folder, creating an opportunity to inject malicious code into a non-existent 'profapi.dll' file. Such manipulation could potentially lead to remote code execution via DLL injection.

Impact

Exploitation of this vulnerability could allow for operating system command injection, with the possibility of remote code execution through DLL injection.

Reproduction

To reproduce this vulnerability, install a vulnerable version of Discord on Windows. During the application's startup, it will load DLL files from the local installation directory. Place a malicious 'profapi.dll' file in the installation folder. The application will load this DLL, allowing the injected code to execute. This process takes advantage of the untrusted search path, where the application fails to verify the integrity of the DLL being loaded.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
4.6
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.