Microsoft Riched Buffer Overflow...

- AV AC AU C I A
发布: 1999-11-17
修订: 2025-04-13

Riched20.dll and Riched32.dll, which Windows uses to parse Rich Text Forrmat files, have an unchecked buffer which allows arbitrary code to be executed. The code can be put into an .rtf file and emailed to the victim. Then if the victim opens the document, the code will be run at the same privilege level as the user. NOTE: It has been reported on the Bugtraq mailing list that the patch provided by Microsoft does not completely fix the problem. A .rtf file with 1000 characters (instead of the original 32) will still crash the application reading the .rtf file.

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息