DLL hijacking is an attack that causes applications to load malicious dynamic link libraries, instead of the intended -clean and legit link libraries- of the Windows system.
Programs that do not specify paths to libraries are vulnerable to DLL hijacking, since Windows uses priority-based searching to load libraries.
If attackers manage to place malicious libraries in a high-priority location, then they will be automatically loaded by the application.
There is nothing users can do about this, as it is not clear whether the paths are set correctly or not in the applications running on the system. It is up to the developers to make sure that the paths are set correctly in the programs before they are made available to the public.
As an end user, you can detect possible DLL hijacking by using a program like Dll Hijack Detect to scan your computer system.
The program detects all DLLs that are loaded by running processes on the system. It inspects all library locations where malicious files may be placed and, in addition, checks if a loaded library appears multiple times in the search queue, determines which library is currently loaded, and warns if there is a possibility of DLL hijacking.
However, every finding does not automatically prove that something is wrong.
For example, the results in the image below are clear, even though the libraries are found in multiple locations on the system.

DLL Hijack Detect is a command line tool that helps detect potential DLL hijacking.
To use it, you can follow these steps:
1. Download the 32-bit or 64-bit version of the program, depending on what your system supports.
2. Unzip the file to a location on your system.
3. Press the Windows key, type cmd.exe, right-click the result, and select Run as administrator to open a command prompt.
4. Navigate to the location where you placed the program.
5. Run dll_hijack_detect_x64.exe or dll_hijack_detect_x32.exe without parameters to scan the system.
All that's left to do is check the results through the report, one by one, to identify if any of the DLL files on your system are hijacked.
