VBScript CRegExp::Execute Uninitialized Memory Use

Discussion in 'News Aggregator' started by Packet Storm, 8 Nov 2016.

  1. Packet Storm

    Packet Storm Guest

    A specially crafted script can cause the VBScript engine to access data before initializing it. An attacker that is able to run such a script in any application that embeds the VBScript engine may be able to control execution flow and execute arbitrary code. This includes all versions of Microsoft Internet Explorer.

    Continue reading...
     

Share This Page

Loading...