Content-Injection Phishing Vulnerability
Technical Details:
=================
Vulnerability Title: Audio Cutter Software - Content-Injection Phishing Vulnerability
Tool Name: Weeny Audio Cutter Software v1.5
Critical Level: Low
Type: Local
Author: Ajay Gowtham aka AJOXR (Blackhat forums)
Type: Software Security Bug
Product Download: http://www.weenysoft.com/free-audio-cutter.html
Overview of Content-Injection Phishing Vulnerability:
=====================================================
Content-Injection Phishing describes the situation where hackers replace part of the content of a legitimate site with false content designed to mislead or misdirect the user into giving up their confidential information to the hacker. For example, hackers may insert malicious code to log user's credentials or an overlay which can secretly collect information and deliver it to the hacker's phishing server.
Technical Impact:
=================
Once the injection is performed by an attacker, when ever next an user uninstalls the vulnerable product from their system could lead to Content-Injection phishing attack which allows user to collect any sensitive information and or deliver feedback form based webpage to gather their personal information.
In this software, affected file "unins000.exe" which fetches file from insecure library and loads the content. where an attacker can able to inject the malicious content. which might be phishing, tabnabbing or spear phishing attacks etc. This allows attacker to gather user information by convencing with fall prey content such as., Win movie tickets, discout coupons etc.
Vulnerability Overview:
=======================
The software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to the users.
Solution:
=========
The file (i.e., "unins000.exe") should sanitize the fetching .htm documents from installed location, in case any user injects the code malicious code should be cross verified for program integrity to avoid content misplacement.
PoC:
====
https://youtu.be/7Ar00dc1XME