ZTE uSmartView DLL Hijacking

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### Vulnerability summary The following advisory describes an DLL Hijacking found in ZTE uSmartView. ZTE uSmartView offers: “ZTE provides full series of cloud computing products (including cloud terminals, cloud desktops, virtualization software, and cloud storage products) and end-to-end integrated product, which can be applied to different scenarios such as office, training classroom, multimedia classroom, and business hall.” ### Credit An independent security researcher has reported this vulnerability to Beyond Security’s SecuriTeam Secure Disclosure program ### Vendor Response ZTE has been notified on the 13th of August 2017, several emails were exchanged, but no ETA for a fix or workaround have been provided for the following vulnerabilities. ### Vulnerability details When uSmartView starts on a Windows machine it tries to load a DLL (pcacli.dll) from the C:\Program Files (x86)\vdc\ientry directory, if a malicious attacker puts the DLL in that directory uSmartView will load it...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息