vendor:
WinDbg
by:
HYP3RLINX
8,8
CVSS
HIGH
Buffer Overflow DOS
119
CWE
Product Name: WinDbg
Affected Version From: 6.3.9600.17298
Affected Version To: 6.3.9600.17298
Patch Exists: YES
Related CWE: CVE-2020-17093
CPE: a:microsoft:windbg:6.3.9600.17298
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2020
MS-WINDBG-LOGVIEWER-BUFFER-OVERFLOW
WinDbg logviewer.exe is prone to a buffer overflow vulnerability when opening corrupted .lgv files. The vulnerability is caused due to a boundary error when handling user-supplied input. A specially crafted .lgv file can cause a buffer overflow, overwriting MMX registers and crashing the application.
Mitigation:
Microsoft has released a patch to address this vulnerability.