Security News Windows: Side-Loading DLL attacks via licensingdiag.exe

Gandalf_The_Grey

Level 83
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 24, 2016
7,233
I'm once again posting information here in the blog that I stumbled across recently. Anyone who is concerned about Windows security should keep an eye on the command line tool licensingdiag.exe. It is another "living of the land" tool that can be used for side-loading DLL attacks. This is because there is an entry in the registry that specifies which DLL is to be loaded from which path.

Dynamic-Link-Library (DLL) side-loading is a method of cyber-attack that takes advantage of the way Microsoft Windows applications handle DLL files. In such attacks, malware places a fake malicious DLL file in a Windows WinSxS directory so that the operating system loads it instead of the legitimate file. Mandiant addresses this issue in this PDF document, for example.

Grzegorz Tworek published the following tweet on X the other day. There he points out that the command line tool licensingdiag.exe contained in Windows offers an opportunity for attacks. Because the tool is included in Windows, it is also referred to as a "living of the land" attack.


 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top