Microsoft Wordpad 5.1 (.doc) Null Pointer Dereference Vulnerability
This vulnerability is caused by a null pointer dereference in Microsoft Wordpad 5.1 (.doc). It is not related to CWE 2009-0259. The proof of concept involves a binary diff of a template file (proper empty doc document) and a malformed file, which shows the offset that differs. Access violation occurs when reading [00000004]. The registers are eax = 020ebb72, ebx = 00000000, ecx = 020ebb7c, edx = 00090608, esi = 00000000, edi = 01bc04a8, eip = 01b9dbbb, esp = 0177f5c8, ebp = 0177f5cc. The function dump is 01b9dbb4 55, 01b9dbb5 8bec, 01b9dbb7 56, 01b9dbb8 8b7508, 01b9dbbb 807e0400, 01b9dbbf 751b, 01b9dbc1 8b06, 01b9dbc3 57, 01b9dbc4 8b78fc, 01b9dbc7 57, 01b9dbc8 ff156010b801, 01b9dbce 57, 01b9dbcf ff157410b801, 01b9dbd5 56, 01b9dbd6 e87bfdffff, 01b9dbdb 5f, 01b9dbdc 5e, 01b9dbdd 5d. Proof of concept is available at http://cond.psychodela.pl/d/ms-wordpad-nullptr.rar and https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/18952.rar.