Advertisement






Microsoft Infotech Storage library Heap Corruption

CVE Category Price Severity
CVE-2017-0003 CWE-122: Heap-based Buffer Overflow $10,000 - $25,000 High
Author Risk Exploitation Type Date
Unknown Critical Remote 2006-05-23
CPE
cpe:cpe:/a:microsoft:infotech_storage_library
CVSS EPSS EPSSP
CVSS:4.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 0.02192 0.50148

CVSS vector description

Our sensors found this exploit at: http://cxsecurity.com/ascii/WLB-2006050083

Below is a copy:

Microsoft Infotech Storage System Library (itss.dll) is prone to a heap
corruption vulnerability. This issue is due to the failure of the
library to properly check a specially crafted CHM file.
The successful exploitation of this flaw would allow to execute
arbitrary code.

Itss.dll is the system library, which deals with CHM/ITS format.

Microsoft rates the CHM file format as potentially dangerous,similar to
an executable file. Nevertheless, this flaw is triggered just
decompiling the malicious CHM file (using hh -decompile), thus malicious
attackers could trick the user to perform this operation or even,
advanced users or researchers could try to decompile before opening it.

Microsoft plans to address this issue in the next Service Pack. Due to
this fact, users of certain Windows versions should implement their own
protection mechanism.

Advisory  and proof of concept available at www.reversemode.com

Regards,
Rubn Santamarta

Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum