|
Microsoft Windows Program Group Converter Filename Local Buffer Overrun Vulnerability
Microsoft Windows Program Group Converter (grpconv.exe) is reported prone to a buffer overrun vulnerability. The issue is reported to exist due to a lack of sufficient validation performed on filename data. An attacker may craft a malicious file and present it to a victim in order to exploit this vulnerability. Additionally, it is demonstrated that this vulnerability may also be exploited using a series of seperate vulnerabilities in Internet Explorer in order to exploit this vulnerability when a malicious website is viewed. It is reported that exploitation may be hindered because parameter data is stored in Unicode format. |
|
|
Privacy Statement |