wbemcomn.dll is naturally found in C:\windows\system32
, however, some WMI serves run with a working directory of C:\windows\system32\wbem
. This means that DLLs might load with a search order hijack by first looking in the working directory.
This DLL hijack appears to at least effect explorer.exe
and the following services:
- WMI
- Windows Update
- WMI Performance Adapter
- WSL