DLL Hijacking Vulnerability in Acer Quick Access Software
CVE-2019-18670
7.8HIGH
What is CVE-2019-18670?
A vulnerability exists in Acer Quick Access allowing a standard user to load arbitrary unsigned DLLs into a signed process running with SYSTEM privileges. This is made possible through an uncontrollable search path for certain DLLs, specifically nvapi.dll, atiadlxx.dll, and atiadlxy.dll. Attackers could exploit this by placing a malicious DLL in a location that the application would erroneously search, leading to unauthorized code execution.