Kindle for PC Arbitrary Code Execution

  Bookmark
 and Share

Kindle for PC is a free application for reading Kindle books. Kindle for PC is exposed to an issue that lets attackers execute arbitrary code. The issue arises because the application searches for the "wintab32.dll" Dynamic Link Library file in the current working directory. Kindle for PC version 1.3.0 Build 30884 is affected.

Ref: http://blogs.technet.com/b/srd/archive/2010/08/23/more-information-about-dll-preloading-remote-attack-vector.aspx

10.50.3 - CVE: Not Available
Platform: Third Party Windows Apps