Habr•August 5, 2026•🇷🇺Translated from Russian

DLL Sideloading via version.dll in WinSCP: Search Order Exploitation, Rust Proxy and Payload Interception

WinSCP loads version.dll from its own folder because Windows follows a deterministic DLL search order that begins with the application directory (AppDir). Researchers published a detailed analysis showing how to detect this vector through static import table review, Known DLLs filtering, and dynamic tracing with Procmon.

The technique mirrors a recent campaign that distributed a trojanized FileZilla build through the fake domain filezilla-project.live, again abusing version.dll. The same actors later compromised the CPUID supply chain (CPU-Z and HWMonitor) using cryptbase.dll.

DLL Search Order and Known DLLs

Windows checks AppDir first, then System32/SysWOW64, and finally PATH. Known DLLs registered under HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\KnownDLLs are loaded exclusively from the system directory, bypassing AppDir entirely. version.dll is absent from this list, leaving it vulnerable to sideloading when placed next to WinSCP.exe.

Static analysis with PE-Bear and the lief Python library revealed that WinSCP.exe directly imports only three functions from version.dll: GetFileVersionInfoSizeW, GetFileVersionInfoW, and VerQueryValueW. This small surface makes proxy implementation straightforward.

Proof-of-Concept Implementation

The Rust cdylib proxy exports all 17 functions of the original library. Fourteen are forwarded at link time via a generated proxy.def file that points to C:\Windows\SysWOW64\version.dll for x86 builds. The three hijacked functions are implemented in Rust and trigger a MessageBoxW payload from a separate thread upon first invocation.

Because WinSCP calls these functions during early initialization, the payload executes before the main application window appears. The real system DLL is loaded lazily only when the forwarded functions are first called, preserving compatibility.

The build script (build.rs) dynamically creates the .def file based on CARGO_CFG_TARGET_ARCH, ensuring correct paths for both 32-bit and 64-bit targets. Release builds enable LTO, symbol stripping, and panic=abort for minimal footprint.

Related articles

Hispasec•Vulnerabilities & Exploits

Critical CVE-2026-61500 in Rejetto HFS Allows Admin Session Forgery Leading to Remote Code Execution

A critical vulnerability tracked as CVE-2026-61500 is being actively exploited in Rejetto HTTP File Server (HFS), enabling unauthenticated attackers to forge administrator sessions and achieve remote code execution. The flaw impacts versions 3.0.0 through 3.2.0 and was addressed in release 3.2.1, making immediate updates essential for any internet-exposed instances. The root cause lies in the use of JavaScript Math.random() to generate the session cookie signing key instead of a cryptographically secure random number generator. Attackers can reconstruct the internal state of this weak PRNG from login responses, allowing them to create valid admin cookies. Once authenticated as an administrator, the attacker can abuse the server_code functionality to execute arbitrary JavaScript on the server. Exploitation activity was first observed on October 1, 2026, targeting U.S. systems and attributed to an unidentified actor based in China, following the public release of a Python proof-of-concept in late September.

BoletimSec•Vulnerabilities & Exploits

Dell Patches Six Critical Flaws in Container Storage Modules for Kubernetes

Dell has fixed six vulnerabilities in its Container Storage Modules that integrate storage systems with Kubernetes clusters. Two of the issues received the maximum CVSS score of 10.0, allowing remote unauthenticated attackers to obtain full administrative credentials for registered storage backends. Additional flaws enable privilege escalation to root on cluster nodes, exposure of hardcoded credentials, and leakage of Kubernetes secrets across the entire cluster. All versions prior to 1.17.0 are affected, with the fixes delivered in version 1.18.0. No workarounds exist, and Dell recommends rotating JWT signing keys after applying the update because the previous keys must be considered compromised.

Security NEXT•Vulnerabilities & Exploits

Critical Sandbox Bypass Flaw in GitLab AI Gateway Enables Remote Command Execution

GitLab has released patches for a critical vulnerability in its GitLab AI Gateway component that allows authenticated users to bypass sandbox restrictions and execute arbitrary commands. The flaw, tracked as CVE-2026-90970, resides in the custom flow prompt template processing of the Duo Agent Platform and carries a CVSS v3.1 base score of 9.9. Self-hosted deployments are affected, while GitLab’s own hosted AI Gateway service has already been updated. The company urges immediate upgrades to versions 19.4.1, 19.3.2, or 19.2.4. The vulnerability can be triggered under specific conditions by users with access to the Duo Agent Platform through crafted flow configurations.

Security NEXT•Vulnerabilities & Exploits

WebPros Releases Critical Patches for Three Vulnerabilities in cPanel & WHM

WebPros International has published security updates addressing three critical vulnerabilities in its cPanel & WHM hosting management platform. All three issues received the highest severity rating of Critical. The flaws include CVE-2026-93698, an input validation weakness in the Multilang adminbin component that could allow root-level operating system command execution. Two additional stored cross-site scripting vulnerabilities were also fixed, one of which is CVE-2026-93697 affecting the Mass Modify Accounts interface in WHM. Successful exploitation of the XSS flaws could let low-privileged accounts hijack administrator sessions. The updates were made available on September 29, 2026, and carry CVSS v3.0 base scores reaching 9.9.