vendor:
Dialer
by:
Unknown
7.5
CVSS
HIGH
Unchecked Buffer
119
CWE
Product Name: Dialer
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE: CVE-2000-0436
CPE: a:dialer:dialer
Platforms Tested:
Unknown
Unchecked Buffer in Dialer.exe
Dialer.exe has an unchecked buffer in the part of the program that reads dialer entries from %systemroot%dialer.ini. A specially-formed entry could cause arbitrary code to be run on the machine. By default, the %systemroot% folder is world-writeable. Dialer.ini is Dialer runs in the security context of the user, so an attacker would have to have a higher authority user dial the entry to gain any escalated privileges.
Mitigation:
Apply the latest patches and updates for the affected software. Restrict write access to the %systemroot%\dialer.ini file. Avoid running the Dialer.exe program with higher authority user accounts.