Microsoft RunDLL32.EXE Buffer Overflow Vulnerability
BID:8114
Info
Microsoft RunDLL32.EXE Buffer Overflow Vulnerability
| Bugtraq ID: | 8114 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 06 2003 12:00AM |
| Updated: | Jul 06 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to Rick Patel <[email protected]>. |
| Vulnerable: |
Microsoft Windows XP Professional SP1 Microsoft Windows XP Home SP1 Microsoft Windows 2000 Server SP4 Microsoft Windows 2000 Professional SP4 Microsoft Windows 2000 Datacenter Server SP4 Microsoft Windows 2000 Advanced Server SP4 |
| Not Vulnerable: | |
Discussion
Microsoft RunDLL32.EXE Buffer Overflow Vulnerability
rundll32.exe has been reported prone to a buffer overflow vulnerability. The condition has been reported to be triggered when an excessive string is passed to the vulnerable application as a routine name for a module.
Exploitation of this issue may be hindered, due to the fact that user-supplied data is converted to Unicode.
It should be noted that although this issue has been reported to affect rundll32.exe that is shipped with Windows XP SP1, other versions might also be affected.
rundll32.exe has been reported prone to a buffer overflow vulnerability. The condition has been reported to be triggered when an excessive string is passed to the vulnerable application as a routine name for a module.
Exploitation of this issue may be hindered, due to the fact that user-supplied data is converted to Unicode.
It should be noted that although this issue has been reported to affect rundll32.exe that is shipped with Windows XP SP1, other versions might also be affected.
Exploit / POC
Microsoft RunDLL32.EXE Buffer Overflow Vulnerability
The following proof of concept has been supplied:
rundll32.exe advpack32.dll,<'A'x499>
The following proof of concept has been supplied:
rundll32.exe advpack32.dll,<'A'x499>
Solution / Fix
Microsoft RunDLL32.EXE Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Microsoft RunDLL32.EXE Buffer Overflow Vulnerability
References:
References:
- Windows XP Homepage (Microsoft)
- Re: rundll32.exe buffer overflow ("wirepair"
)