New issue
Advanced search Search tips

Issue 603477 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Apr 2016
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

DLL Injection

Reported by mahendra...@gmail.com, Apr 14 2016

Issue description

VULNERABILITY DETAILS
Found DLL injection in the google chrome. Successfully injected the injectdll.dll into the google chrome process address space. DLL is successfully executed and temp file is created. likewise we can create windows user also by writing DLL for the same.

VERSION
Chrome Version: Version 50.0.2661.75 m 
Operating System: Windows 7 Professional Service Pack1

REPRODUCTION CASE
1)Create A DLL File to inject into process.
2)Pass Process ID and DLL file path as input to the program.
3)Execute the program written in C++ to inject the DLL into the chrome memory address space.
4)On successful exploitation DLL file will be injected into process address space and executed.
5)On DLL file execution temp file will be created as i have written the same code for DLL file.
 
Security Flaw in the Chrome Browser.pdf
542 KB Download
The Same attack is restricted by other application as they don't allow to execute the unwanted DLL.
Project Member

Comment 3 by sheriffbot@chromium.org, Jul 22 2016

Labels: -Restrict-View-SecurityTeam
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 4 by sheriffbot@chromium.org, Oct 1 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 5 by sheriffbot@chromium.org, Oct 2 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: allpublic

Sign in to add a comment