ActiveSetupN.exe in Amazon Audible for Windows before November 2017 allows attackers to execute arbitrary DLL code if ActiveSetupN.exe is launched from a directory where an attacker has already created a Trojan horse dwmapi.dll file.
- https://packetstormsecurity.com/files/145202/Amazon-Audible-DLL-Hijacking.html
No PoCs found on GitHub currently.