VBScript RegExpComp::PnodeParse Out-Of-Bounds Read
Posted by deepcore on November 12, 2016 – 1:59 am
A specially crafted script can cause the VBScript engine to read data beyond a memory block for use as a regular expression. An attacker that is able to run such a script in any application that embeds the VBScript engine may be able to disclose information stored after this memory block. This includes all versions of Microsoft Internet Explorer.
Post a reply
You must be logged in to post a comment.