vendor:
Windows Mobile 6
by:
Julien Bedard
7.8
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: Windows Mobile 6
Affected Version From: Windows Mobile 6
Affected Version To: Windows Mobile 6
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: HTC wiza 200, HTC Mda 8125
2008
WM6 remote overflow reboot PoC
This PoC shows the first method of exploiting a buffer overflow vulnerability in Windows Mobile 6 devices. The bug is not realy in the long string name but when it's the first time the wm6 device try to get a connection with too long name. There are two ways to exploit this bug, this PoC show the first method (direct connect to the device if we know the bdaddr) but you can just wait for the device to search and overflow by itself when seeing the hci name.
Mitigation:
The user should ensure that the device is not exposed to maliciously crafted input.