
JVicente928307 (Community Member) asked a question.
Hello
CWE-506: Embedded Malicious Code.
In module syncfusion.shared.base.dll at locations:
void AddCallWndProcListener(ICallWndProcListener) /// Syncfusion.Windows.Forms.Tools.Design.ThreadHooks
void AddGetMsgProcListener(IGetMsgProcListener) /// Syncfusion.Windows.Forms.Tools.Design.ThreadHooks
void HookMessage() /// Syncfusion.Windows.Forms.MouseProcHookerUtil
void HookMessage() /// Syncfusion.Windows.Forms.KeyboardProcHooker
Thanks!
.png)
Flaws shows up in a static scan.
The syncfusion.shared.base.dll module needs to be scanned.
So, what can we do?
Is it a false positive or can it be mitigated?
Hi,
Veracode Static Analysis detects using of very dangerous functionality as the potential for 'embedded malicious code'.
We strongly recommend you work with the code authors to determine why this functionality is in place. 'Hooking into' all mouse and keyboard interactions is very powerful and dangerous functionality that may have legitimate usage but should be carefully auditted.
I would recommend you schedule a consultation call to discuss.
You can check out this knowledge article (https://community.veracode.com/s/article/How-to-schedule-a-consultation-call) on how to schedule a consultation call with us.
Thank you,
Boy Baukema