Humming Heads Defense Platform Home Edition Windows Messaging Channel Vulnerability Allowing Arbitrary File Modification and DLL Execution with SYSTEM Privilege
Vulnerability
A vulnerability exists in Humming Heads Defense Platform Home Edition versions through 3.9.51.x, related to the unprotected Windows messaging channel known as 'Shatter'. This vulnerability allows an attacker to send a specially crafted message to a specific process on the Windows system where the product is running. As a result, arbitrary files on the system may be altered, leading to the execution of an arbitrary DLL with SYSTEM privileges.
Impact
Exploitation of this vulnerability could result in unauthorized modification of system files and the execution of malicious DLLs with SYSTEM privileges, potentially allowing for significant control over the affected system.
Remediation
Users are advised to update Defense Platform Home Edition to version 3.9.52.5 or later, where this vulnerability has been addressed. Instructions for downloading the latest version are available on the Humming Heads website.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
