CompTIA Security+ (SY0-701)Threats, Vulnerabilities, and MitigationsHard

A security researcher analyzing a Windows application finds that it loads a required library by searching the current working directory before checking the trusted system directory. An attacker places a malicious library with the same filename in a folder the application will search first, causing the malicious code to execute with the application's privileges. Which attack technique is being described?

  1. ABuffer overflow
  2. BDLL sideloading
  3. CRace condition exploitation
  4. DCross-site scripting
Show answer & explanation

Correct answer: B. DLL sideloading

DLL sideloading (also called DLL hijacking) exploits an application's insecure search order for shared libraries, tricking it into loading a malicious DLL from an attacker-controlled location instead of the legitimate system library, resulting in code execution under the application's privileges.

Why the other options are wrong

  • A. Buffer overflow overwrites memory with oversized input, not library loading order.
  • C. A race condition exploits timing between check and use, not file path/library search order.
  • D. Cross-site scripting targets web browsers executing injected script, unrelated to local DLL loading.

DLL Sideloading (Hijacking)

An attack that exploits an application's insecure DLL search order to load a malicious library instead of the legitimate one, achieving code execution with the app's privileges.

  • Exploits Windows library search order precedence
  • Malicious DLL is placed in a directory searched before the trusted system path
  • Mitigated by using fully qualified library paths and secure search settings

Memory trick: Sideloading swaps in a fake library book before you reach the real shelf.

More Threats, Vulnerabilities, and Mitigations questions