NVIDIA NvStreamKms PsSetCreateProcessNotifyRoutineEx Stack Buffer Overflow

Discussion in 'News Aggregator' started by Packet Storm, 31 Oct 2016.

  1. Packet Storm

    Packet Storm Guest

    The NvStreamKms.sys driver calls PsSetCreateProcessNotifyRoutineEx to set up a process creation notification routine. wcscpy_s is used incorrectly here, as the second argument is not the size of |Dst|, but rather the calculated size of the filename. |Dst| is a stack buffer that is at least 255 characters long. The the maximum component paths of most filesystems on Windows have a limit that is b/c/...", leading to a buffer overflow. Additionally, this function has no stack cookie.

    Continue reading...
     

Share This Page

Loading...