
DLL Planting in the Slack 4.33.73 - CVE-2023-38820
DLL Planting in the Slack 4.33.73 - CVE-2023-38820 Discoverer: Idan Malihi
An issue in Slack Slack v.4.33.73 allows a local attacker to execute arbitrary code via the DLL loading mechanism in profapi.dll, CRYPTBASE.dll, KBDUS.DLL, DPAPI.dll, MSASN1.dll, mf.dll, mfplat.dll, and RTWorkQ.DLL files.
To exploit the vulnerability, an attacker should download and install the Slack program, and follow the steps: