Seagate Toolkit Installer Insecure DLL Loading Vulnerability Allowing Arbitrary Code Execution
Vulnerability
A vulnerability has been identified in the Seagate Toolkit Installer for Windows, prior to version 2.35.0.6. The issue arises because the installer loads DLLs from the current working directory without verifying their source or integrity. This flaw can be exploited by placing a malicious DLL in the same directory as the installer executable, which could lead to arbitrary code execution with the privileges of the user running the installer. The vulnerability is rooted in unsafe DLL loading practices, such as using relative paths or not specifying fully qualified paths when calling system libraries.
Impact
Exploitation of this vulnerability allows for arbitrary code execution with the privileges of the user running the Seagate Toolkit Installer.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
