|
Google Chrome is prone to a flaw in the way it loads NPAPI plugins such as the Windows Media Player plugin. The program uses a fixed path to look for specific files or libraries. This path includes directories (e.g. '%SYSTEMROOT%\PFiles\Plugins\') that may not be trusted or under user control. By placing a custom version of the file or library in the path, the program will load it before the legitimate version. This allows a local attacker to inject custom code that will be run with the privilege of the program or user executing the program.
|