vendor:
by:
Nicolas Joly, 4B5F5F4B, juan vazquez
N/A
CVSS
N/A
integer overflow
CWE
Product Name:
Affected Version From:
Affected Version To:
Patch Exists:
Related CWE: CVE-2013-2551
CPE:
Platforms Tested: Windows 7 SP1 with IE8
MS13-009 Microsoft Internet Explorer COALineDashStyleArray Integer Overflow
This module exploits an integer overflow vulnerability on Internet Explorer. The vulnerability exists in the handling of the dashstyle.array length for vml shapes on the vgx.dll module. This module has been tested successfully on Windows 7 SP1 with IE8. It uses the the JRE6 to bypass ASLR by default. In addition a target to use an info leak to disclose the ntdll.dll base address is provided. This target requires ntdll.dll v6.1.7601.17514 (the default dll version on a fresh Windows 7 SP1 installation) or ntdll.dll v6.1.7601.17725 (version installed after apply MS12-001).