Desktop Software

Memory Corruption

OOB Write Heap Buffer dwCompressionSize MS-WIM

Quick Heal Internet Security Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability We found that the Quick Heal Internet Security is vulnerable to Out of Bound Write…

9.8
/ 10
Critical
CVSS v3.1
ADVISORY ID
PS7
PUBLISHED
2022-10-02
CVE IDs
CVE-2017-8773
VENDORS
Quick Heal
PUBLIC EXPLOIT
None indexed
CWE
CWE-787
PRODUCT
Quick Heal Internet Security / Total Security / AntiVirus Pro
CVSS VECTOR
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Abstract blurred background with dark tones and smooth gradient waves of blue, purple, and orange hues.
Summary

Overview

Quick Heal Internet Security Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

We found that the Quick Heal Internet Security is vulnerable to Out of Bound Write on Heap Buffer due to improper validation of dwCompressionSize of Microsoft WIM Header WIMHEADER_V1_PACKED.

This vulnerability can be exploited to gain Remote Code Execution as well as Privilege Escalation.

Vulnerability details

Vulnerability details

CVE-2017-8773
CWE-787
Critical | 9.8

Quick Heal Internet Security Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability We found that the Quick Heal Internet Security is vulnerable to Out of Bound Write on Heap Buffer due to improper validation of

Auth:
None (remote)
Impact:
Sensitive data disclosure, arbitrary data or code modification, denial of service
DISCLOSURE

Disclosure timeline

2016-07-13 Reported to vendor

2016-07-15 Received acknowledgement from vendor

2016-07-20 Patch released

References

Credits

Ashfaq Ansari – Project Srishti – Payatu Technologies