Posted by Mario Vilas on Sep 05
Paul,
Those file extensions correspond to scripts. If a file contains a script
that runs when the file is double clicked, and the scripting engine is not
sandboxed (meaning the script can do the same things an executable file can
do) then the attack is meaningless. You can simply have the script inside
the file do malicious things instead of planting a DLL.
Binary planting, regardless of the discussion about it being a
"vulnerability"…
Source: Re: Cybsec Advisory 2011 0901 Windows Script Host DLL Hijacking




