Subscribe via feed.
Archive for October, 2015

.NET Partial-Trust Bypass

Posted by deepcore under exploit (No Respond)

A command-line injection vulnerability exists in the core .NET class System.Windows.Forms.Help::ShowHelp function allowing an attacker without “UnmanagedCode” permission to nevertheless directly control arguments passed to a “ShellExecute” invocation of the users’ default browser. This vulnerability allows an attacker who is able to run arbitrary .NET code within a .NET PartialTrust sandbox including the “WebPermission” permission […]

Kerio Control 8.6.1 SQL Injection / Code Execution / CSRF

Posted by deepcore under exploit (No Respond)

Kerio Control versions 8.6.1 and below suffer from remote SQL injection and remote code execution through cross site request forgery vulnerabilities.

Kaspersky Antivirus CHM Parsing Remote Stack Buffer Overflow

Posted by deepcore under exploit (No Respond)

Fuzzing CHM files with Kaspersky Antivirus produced a crash due to a stack buffer overflow vulnerability.

Kaspersky Antivirus ExeCryptor Parsing Memory Corruption

Posted by deepcore under exploit (No Respond)

Fuzzing packed executables in Kaspersky Antivirus found an ExeCryptor parsing memory corruption vulnerability.

Kaspersky Antivirus PE Unpacking Integer Overflow

Posted by deepcore under exploit (No Respond)

Kaspersky Antivirus PE unpacking suffers from an integer overflow vulnerability.

Kaspersky Antivirus UPX Parsing Remote Memory Corruption

Posted by deepcore under exploit (No Respond)

While fuzzing UPX packed files in Kaspersky Antivirus, a crash was discovered resulting in an arbitrary stack-relative write. This vulnerability is obviously remotely exploitable for remote code execution as NT AUTHORITYSYSTEM.

Kaspersky Antivirus Yoda's Protector Unpacking Remote Memory Corruption

Posted by deepcore under exploit (No Respond)

The attached testcase was found by fuzzing packed PE files with Kaspersky Antivirus. The researcher suspects it was packed using “Yoda’s protector”. This vulnerability is obviously exploitable for remote code execution as NT AUTHORITYSYSTEM on all systems using Kaspersky Antivirus.

Avast Antivirus X.509 Error Rendering Command Execution

Posted by deepcore under exploit (No Respond)

Avast will render the commonName of X.509 certificates into an HTMLLayout frame when your MITM proxy detects a bad signature.

K2 SmartForms / BlackPearl SQL Injection

Posted by deepcore under exploit (No Respond)

K2 SmartForms, BlackPearl, and K2 for Sharepoint version 4.6.7 suffer from a boolean-based remote SQL injection vulnerability.

[webapps] – ZyXEL PMG5318-B20A – OS Command Injection Vulnerability

Posted by deepcore under Security (No Respond)

ZyXEL PMG5318-B20A – OS Command Injection Vulnerability

Tags: ,