Microsoft Windows LoadImage API Function Integer Overflow Vulnerability

A proof-of-concept exploit is available from the following location:

http://www.xfocus.net/flashsky/icoExp/index.html

UPDATE: Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.


 

Privacy Statement
Copyright 2010, SecurityFocus