Blog | G5 Cyber Security

Musings on Information Security and Data Privacy: CVE-2010-x+n

After Acrossecurity, published an interesting vulnerability and HDmoore appears to have stumbled on the same issue, I decided to investigate on my own. While it is known since years and Microsoft even dedicates a KB article to it, vendors appear to still have issues with using Loadlibrary/Getprocadress correctly. This issue appears to be first discovered by Georgi Guninski (who else) in 2000, so it is not a new weakness and defensive mechanisms have been introduced into development languages as well as windows itself to mitigate this risk.”]

Source: https://blog.zoller.lu/2010/08/cve-2010-xn-loadlibrarygetprocaddress.html

Exit mobile version