
Proof of concept (exploit) for CVE-2024-6473
Yandex Browser for Desktop before 24.7.1.380 has a DLL Hijacking Vulnerability because an untrusted search path is used.
[!IMPORTANT] The Internet must be turned off during installation, otherwise the browser will be updated.
You can download vulerable version from download.cdn.yandex.net
Or usage from archive
I used the "LolNope" approach from here: https://github.com/advancedmonitoring/ProxyDll
You just need to compile the DLL file and place it in the path %LOCALAPPDATA%\Yandex\YandexBrowser\Application and start the browser
