T07 · Tool Hijacking and Spoofing
- Location
scripts/dwg_to_dxf.py:35- Finding
Untrusted ODA Converter Resolution Through the Process PATH
- Content
View full analysis
Vulnerability Details
File Location:
scripts/dwg_to_dxf.py, lines 35–36 and 90–98
Vulnerability Type: Executable search-path hijacking
Risk Level: MediumVulnerable Code
python # 3. 尝试从系统环境变量查找 found = shutil.which("ODAFileConverter.exe") or shutil.which("ODAFileConverter") return foundThe resolved path is subsequently executed:
python result = subprocess.run( cmd, capture_output=True, text=True, check=True, creationflags=creation_flags, timeout=180 )Technical Analysis
If the converter is unavailable at the bundled path and fixed system installation paths,
find_oda_engine()searches the processPATHfor an executable namedODAFileConverter.exeorODAFileConverter. The returned executable is trusted and launched without validating its cryptographic hash, publisher signature, ownership, or filesystem permissions.The audited project does not include the declared
tools/oda/ODAFileConverter.exe, making fallback resolution relevant. Althoughsubprocess.run()correctly receives an argument list and does not introduce shell-command injection, that protection does not prevent executable search-path hijacking.An attacker must already be able to influence the Agent process environment or write a matching executable into a directory searched before the legitimate converter. Under those conditions, a malicious binary can impersonate ODA File Converter and execute attacker-controlled logic when conversion is requested.
Attack Path
- The trusted converter is absent from
tools/oda/and the fixed installation locations. - An attacker places a malicious executable named
ODAFileConverter.exeorODAFileConverterin a writable directory. - The attacker causes that directory to appear in the Agent process
PATH, ahead of any legitimate converter location. - A user or workflow invokes
scripts/dwg_to_dxf.pyfor a DWG conversion. shutil.which()resolves the attacker-control ...[truncated 626 chars]
- The trusted converter is absent from
- Remediation
View remediation
Remediation Suggestions
- Remove the
PATH-based fallback and require either the bundled converter or an explicitly configured absolute executable path. - Before execution, validate the converter using a pinned cryptographic hash or an expected Authenticode publisher and certificate chain.
- Reject relative paths and confirm that the resolved path is a regular file in an administrator-controlled directory.
- Verify that the executable and its parent directories are not writable by untrusted users.
- Launch the converter under a dedicated least-privileged account or sandbox with access limited to the required input, temporary, and output directories.
- Fail closed with a clear installation error when no verified converter is available.
- If
PATHdiscovery must remain for compatibility, restrict discovery to an explicit allowlist of trusted directories and perform integrity verification before every launch.
- Remove the
