Описание
Arm Whois 3.11 contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by overwriting the structured exception handler. Attackers can craft a malicious input file with a 672-byte offset to overwrite the nSEH and SEH pointers, enabling code execution through exception handler hijacking.
EPSS
Процентиль: 6%
0.00162
Низкий
8.4 High
CVSS3
Дефекты
CWE-120
Связанные уязвимости
CVSS3: 8.4
github
3 месяца назад
Arm Whois 3.11 contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by overwriting the structured exception handler. Attackers can craft a malicious input file with a 672-byte offset to overwrite the nSEH and SEH pointers, enabling code execution through exception handler hijacking.
EPSS
Процентиль: 6%
0.00162
Низкий
8.4 High
CVSS3
Дефекты
CWE-120