Desktop Software

Memory Corruption

OOB Write Stack Buffer LC_UNIXTHREAD.cmdsize Mach-O

Quick Heal Internet Security Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability We found that the Quick Heal Internet Security is vulnerable to Out of Bound Write…

9.8
/ 10
Critical
CVSS v3.1
ADVISORY ID
PS5
PUBLISHED
2022-10-02
CVE IDs
CVE-2017-5005
VENDORS
Quick Heal
PUBLIC EXPLOIT
PoC public
CWE
CWE-787
PRODUCT
Quick Heal Internet Security / Total Security / AntiVirus Pro
CVSS VECTOR
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Abstract blurred background with dark tones and smooth gradient waves of blue, purple, and orange hues.
Summary

Overview

Quick Heal Internet Security Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

We found that the Quick Heal Internet Security is vulnerable to Out of Bound Write on Stack Buffer due to improper validation of LC_UNIXTHREAD.cmdsize (Mach-O).

This vulnerability can be exploited to gain Remote Code Execution as well as Privilege Escalation.

Vulnerability details

Vulnerability details

CVE-2017-5005
CWE-787
Critical | 9.8

Quick Heal Internet Security Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability We found that the Quick Heal Internet Security is vulnerable to Out of Bound Write on Stack Buffer due to improper validation of

Auth:
None (remote)
Impact:
Sensitive data disclosure, arbitrary data or code modification, denial of service
DISCLOSURE

Disclosure timeline

2016-06-09 Reported to vendor

2016-06-11 Received acknowledgement from vendor and patch released

References

Credits

Ashfaq Ansari – Project Srishti – Payatu Technologies