CompTIA Security+ (SY0-701)Threats, Vulnerabilities, and MitigationsHard
A security researcher analyzing a Windows application finds that it loads a required library by searching the current working directory before checking the trusted system directory. An attacker places a malicious library with the same filename in a folder the application will search first, causing the malicious code to execute with the application's privileges. Which attack technique is being described?
- ABuffer overflow
- BDLL sideloading
- CRace condition exploitation
- DCross-site scripting
Show answer & explanationAnswer & explanation
Correct answer: B. DLL sideloading
DLL sideloading (also called DLL hijacking) exploits an application's insecure search order for shared libraries, tricking it into loading a malicious DLL from an attacker-controlled location instead of the legitimate system library, resulting in code execution under the application's privileges.
Why the other options are wrong
- A. Buffer overflow overwrites memory with oversized input, not library loading order.
- C. A race condition exploits timing between check and use, not file path/library search order.
- D. Cross-site scripting targets web browsers executing injected script, unrelated to local DLL loading.
DLL Sideloading (Hijacking)
An attack that exploits an application's insecure DLL search order to load a malicious library instead of the legitimate one, achieving code execution with the app's privileges.
- Exploits Windows library search order precedence
- Malicious DLL is placed in a directory searched before the trusted system path
- Mitigated by using fully qualified library paths and secure search settings
Memory trick: Sideloading swaps in a fake library book before you reach the real shelf.