Junglewise Threat Intelligence

CVE-2016-1417: Cisco Snort DLL hijacking in tcapi.dll

CVE-2016-1417 · Severity: high · CVSS 8.8 · Published 2017-01-23

Vendors: Cisco.

Executive brief

Snort is a widely used network intrusion detection system that monitors network traffic for malicious activity. A vulnerability in the Windows version of Snort allows an attacker to execute malicious code on a user's system if the user is tricked into opening a network capture file (pcap) from a malicious remote folder. This could lead to a full system compromise, allowing an attacker to steal data or disrupt network monitoring operations.

Technical details

An untrusted search path vulnerability (CWE-426) exists in Snort v2.9.7.0-WIN32. The application attempts to load the 'tcapi.dll' library without using a fully qualified path. If a user opens a .pcap file located on a remote file share (e.g., via SMB), the Windows loader may search the directory containing the pcap file for required DLLs. An attacker can place a malicious 'tcapi.dll' in the same remote directory as a pcap file; when Snort processes the pcap, it loads and executes the attacker's DLL. This requires user interaction to open the file from the untrusted location but results in arbitrary code execution with the privileges of the Snort process.

Affected products

  • Cisco Snort 2.9.7.0-WIN32

Timeline

  • 2016-04-21: disclosed: Vendor notified
  • 2016-09-29: advisory: Public disclosure by researcher
  • 2017-01-23: advisory: NVD publication date

References