Exploit Microsoft Windows Kernel - Pool Buffer Overflow Drawing Caption Bar (MS15-061)

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
38268
Проверка EDB
  1. Пройдено
Автор
NILS SOMMER
Тип уязвимости
DOS
Платформа
WINDOWS_X86
CVE
cve-2015-1727
Дата публикации
2015-09-22
Microsoft Windows Kernel - Pool Buffer Overflow Drawing Caption Bar (MS15-061)
Код:
Source: https://code.google.com/p/google-security-research/issues/detail?id=321

The PoC triggers a crashes due to a pool buffer overflow while drawing the caption bar of window.  The trigger depends on the current window layout and resolution. The PoC takes an offset on the command line to be able to test with different values, I tested this on two different Win7 32-bit VM's and had success with 0 and 475000 (Resolution was 1024x768 and 1280x1024). A bruteforce Python script is also attached which should trigger a crash fairly quickly.

Proof of Concept:
https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/38268.zip
 
Источник
www.exploit-db.com

Похожие темы