Description
DLL hijacking is possible in Sublime Text 3 version 3.1.1 build 3176 on 32-bit Windows platforms because a Trojan horse api-ms-win-core-fibers-l1-1-1.dll or api-ms-win-core-localization-l1-2-1.dll file may be loaded if a victim uses sublime_text.exe to open a .txt file within an attacker's %LOCALAPPDATA%\Temp\sublime_text folder. NOTE: the vendor's position is "This does not appear to be a bug with Sublime Text, but rather one with Windows that has been patched.
Published: 2019-02-25
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

No history.

Subscriptions

Microsoft Windows 7
Sublimetext Sublime Text 3
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T21:38:46.520Z

Reserved: 2019-02-24T00:00:00.000Z

Link: CVE-2019-9116

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-02-25T07:29:00.190

Modified: 2024-11-21T04:51:01.097

Link: CVE-2019-9116

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses