vendor:
Windows
by:
Victor Portal (vportal)
7.5
CVSS
HIGH
Memory Corruption (Heap Overflow)
CWE
Product Name: Windows
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows Server 2003 SP2
ErraticGopher Exploit
The ErraticGopher exploit is a python version of the ErraticGopher exploit with some modifications. It exploits a memory corruption vulnerability (Heap Overflow) in the Windows DCE-RPC Call MIBEntryGet. By redirecting the execution to the iprtrmgr.dll library, it overwrites a return address and the SEH handler stored in the stack, allowing the control of execution flow to disable DEP and jump to the shellcode as SYSTEM user.
Mitigation:
Ensure RRAS service is disabled if not needed. Regularly apply security patches and updates.