vendor:
Windows
by:
.einstein., dH team
9.8
CVSS
CRITICAL
Buffer Overflow
119
CWE
Product Name: Windows
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE: CVE-XXXX-XXXX
CPE: o:microsoft:windows
Platforms Tested: Windows
Unknown
Buffer Overflow in .ShellClassInfo
This exploit takes advantage of a buffer overflow vulnerability in the .ShellClassInfo section of the Windows operating system. It allows an attacker to execute arbitrary code by providing a specially crafted URL. The exploit contains shellcode that downloads and executes additional code from a remote location.
Mitigation:
Apply the latest security patches from the vendor. Avoid opening URLs from untrusted sources.