Security researchers have uncovered serious zero-day vulnerabilities related to DLL hijacking in various applications developed by Corel Software. This flaw could potentially enable attackers to execute arbitrary commands on victimized systems, affecting over 100 million users globally. The disclosure comes from vulnerability researcher Marcos Accossatto of Core Security, who made the vulnerabilities public after Corel failed to respond to prior notifications regarding the issues.
Corel Software is renowned for its diverse suite of products, which includes tools for graphics, photo editing, video creation, and other multimedia functions. The identified vulnerabilities arise when specific media files associated with Corel programs are opened. During this process, if a similarly named DLL (Dynamic Link Library) file is present in the same directory as the media file, the Corel application loads the DLL into memory. This behavior opens a door for cybercriminals to exploit the situation by placing malicious DLLs in the directory, allowing them to install malware on the target system.
Accossatto advises users to exercise extreme caution and avoid opening untrusted files linked to Corel software, especially those that could include the compromised DLLs. He highlighted the high-risk nature of this client-side vulnerability, warning that it permits attackers to execute arbitrary commands by simply placing harmful DLL files next to legitimate documents.
The range of Corel products affected by these vulnerabilities is broad, encompassing at least eight applications, including CorelDRAW X7, Corel Photo-Paint X7, and Corel VideoStudio PRO X7, among others. Despite notifying Corel of the vulnerabilities on December 9, 2014, along with a follow-up reminder, the company did not provide any acknowledgment or corrective measures. Consequently, the Core Security team opted to publicly disclose the vulnerabilities to alert users to this significant risk.
In response to the findings, Corel has not yet released any patches for the identified vulnerabilities. A representative from Corel, Jessica Gould, stated that the company is evaluating its software on a case-by-case basis to address the dynamic loading of DLL files, a common risk associated with many Windows applications. She noted that updates focusing on these vulnerabilities are being prioritized for future releases of affected Corel products.
As this situation develops, it is critical for business owners and IT professionals to remain vigilant. The attack vector aligns with adversary tactics outlined in the MITRE ATT&CK framework, specifically initial access through exploiting software vulnerabilities. The persistence of potential threats underscores the necessity for robust security measures, including avoiding the opening of suspicious files and regularly updating software to mitigate associated risks.
The lack of immediate exploits reported thus far may suggest a temporary reprieve, but the significant number of users potentially exposed means that vigilance remains paramount. As organizations increasingly rely on Corel software for creative processes, understanding these vulnerabilities and their potential implications for cybersecurity is essential. Businesses should proactively assess their security policies to safeguard against such exploits in the future.