
"Emerging DLL Hijacking Variant Circumvents Windows 10/11 Security Measures"
Security Joes has discovered a new variant of DLL search order hijacking that bypasses security in Windows 10 and 11 by exploiting trusted executables in the WinSxS folder. This technique allows attackers to execute malicious code without needing elevated privileges and introduces vulnerable binaries into the attack chain. The method involves placing a malicious DLL with the same name as a legitimate one in a controlled directory to achieve code execution when a vulnerable file in the WinSxS folder is executed. Organizations are advised to monitor process relationships and activities of binaries in the WinSxS folder to mitigate this threat.