Description
Arm Whois 3.11 contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by overwriting the structured exception handler. Attackers can craft a malicious input file with a 672-byte offset to overwrite the nSEH and SEH pointers, enabling code execution through exception handler hijacking.
Problem types
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Product status
Credits
zephyr
References
www.exploit-db.com/exploits/45907 (ExploitDB-45907)
www.armcode.com (Official Product Homepage)
www.armcode.com/downloads/arm-whois.exe (Product Reference)
www.vulncheck.com/...m-whois-buffer-overflow-via-aslr-bypass (VulnCheck Advisory: Arm Whois 3.11 Buffer Overflow via ASLR Bypass)