In handle_app_cur_val_response of dtif_rc.cc, there is a possible stack buffer overflow due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

DoublePulsar


Cybersecurity from the trenches, written by Kevin Beaumont. Opinions are of the author alone, not their employer.

Listed: