CAPEC-641: DLL Side-Loading

Attack Pattern ID: 641
Abstraction: Detailed
Status: Stable
+ Description
An adversary places a malicious version of a Dynamic-Link Library (DLL) in the Windows Side-by-Side (WinSxS) directory to trick the operating system into loading this malicious DLL instead of a legitimate DLL. Programs specify the location of the DLLs to load via the use of WinSxS manifests or DLL redirection and if they aren't used then Windows searches in a predefined set of directories to locate the file. If the applications improperly specify a required DLL or WinSxS manifests aren't explicit about the characteristics of the DLL to be loaded, they can be vulnerable to side-loading.
ChildOfStandard Attack PatternStandard Attack Pattern - A standard level attack pattern in CAPEC is focused on a specific methodology or technique used in an attack. It is often seen as a singular piece of a fully executed attack. A standard attack pattern is meant to provide sufficient details to understand the specific technique and how it attempts to accomplish a desired goal. A standard level attack pattern is a specific type of a more abstract meta level attack pattern.159Redirect Access to Libraries
+ Prerequisites
The target must fail to verify the integrity of the DLL before using them.
+ Skills Required
[Level: High]
Trick the operating system in loading a malicious DLL instead of a legitimate DLL.
Execute Unauthorized Commands
Bypass Protection Mechanism
+ Mitigations
Prevent unknown DLLs from loading through whitelisting policy.
Patch installed applications as soon as new updates become available.
Properly restrict the location of the software being used.
Use of sxstrace.exe on Windows as well as manual inspection of the manifests.
Require code signing and avoid using relative paths for resources.
1073DLL Side-Loading
[REF-501] Stewart A.. "DLL SIDE-LOADING: A Thorn in the Side of the Anti-Virus Industry". FireEye. <https://www.fireeye.com/content/dam/fireeye-www/global/en/current-threats/pdfs/rpt-dll-sideloading.pdf>.
2018-07-31CAPEC Content TeamThe MITRE Corporation

