|
|
| |
| Doro is a free tool to create pdf files from any Windows program. A vulnerability in the product allows local users to gain elevated privileges. |
| |
Credit:
The information has been provided by Ramon Kukla.
|
| |
Vulnerable systems:
* Doro version 1.13
After installing Doro you have a new printer called 'Doro PDF Writer'. If you select 'Print' the spooler calls the printer filter 'doro.dll'. The 'doro.dll' then starts 'doro.exe' and a file requester appears. This means that replacing the 'doro.exe' file with a Trojan will allow a local users to compromise the server, as the spooler is controlled by the account 'system' (therefore the file requester has the same rights).
|
|
|
|
|