DLL Search Order Hijacking in Opera Browser
CVE-2018-18913
7.8HIGH
What is CVE-2018-18913?
Opera Browser prior to version 57.0.3098.106 is susceptible to a DLL Search Order hijacking vulnerability. This flaw allows an attacker to craft a ZIP archive containing an HTML page paired with a malicious DLL file. When the compromised document is executed, the browser searches its system directory for the required DLLs—specifically shcore.dll and dcomp.dll. This behavior can inadvertently facilitate an attacker in executing arbitrary code, potentially leading to full system control. Users of affected versions are advised to update their browsers immediately to mitigate any security risks associated with this vulnerability.