Anthropic Claude for Windows DLL Search Order Hijacking Vulnerability Allowing Local Privilege Escalation
Vulnerability
A vulnerability in the Anthropic Claude for Windows installer, specifically in versions prior to 1.1.3363, allows for local privilege escalation through DLL search-order hijacking. The installer improperly manages search path elements, leading to a scenario where it loads DLLs, such as profapi.dll, from its own directory after User Account Control (UAC) elevation. This behavior enables arbitrary code execution if a malicious DLL is placed alongside the installer.
Impact
Exploitation of this vulnerability could lead to unauthorized privilege escalation and arbitrary code execution on the affected system.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
