vendor:
SymCrypt
by:
Exploit Database
7.5
CVSS
HIGH
Infinite Loop Vulnerability
835
CWE
Product Name: SymCrypt
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows
2020
SymCrypt Multi-Precision Arithmetic Routines Infinite Loop Vulnerability
There's a bug in the SymCrypt multi-precision arithmetic routines that can cause an infinite loop when calculating the modular inverse on specific bit patterns with bcryptprimitives!SymCryptFdefModInvGeneric. It can be triggered by constructing an X.509 certificate and embedding it in an S/MIME message, authenticode signature, schannel connection, etc. This will effectively DoS any Windows server and may require the machine to be rebooted.
Mitigation:
Upgrade to the latest version of SymCrypt to fix the vulnerability.