DLL Hijacking / DLL Sideloading vulnerability in Microsoft OneDrive. FileCoAuthLib64.dll is loaded without signature verification, allowing DLL replacement and persistent code execution at user privilege level.
microsoft windows security research persistence reverse-engineering onedrive poc vulnerability dll-injection bypassing dll-hijacking security-research redteam vulnerability-research injection-attacks hijacking bypass-security dll-sideloading
-
Updated
Sep 7, 2026 - C