NT Malformed Dialer Entry Vulnerability...

- AV AC AU C I A
发布: 1999-07-30
修订: 2025-04-13

Dialer.exe has an unchecked buffer in the part of the program that reads dialer entries from %systemroot%\dialer.ini. A specially-formed entry could cause arbitrary code to be run on the machine. By default, the %systemroot% folder is world-writeable. Dialer.ini is Dialer runs in the security context of the user, so an attacker would have to have a higher authority user dial the entry to gain any escalated priveleges.

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息