Quantcast
Channel: BOT24
Viewing all articles
Browse latest Browse all 8064

Symantec Endpoint Protection Manager – CVE-2013-1612 – Remote Buffer Overflow – PoC

$
0
0
Do want to help me to turn this PoC into reliable exploit code ? Here is the short story about CVE-2013-1612, a remote buffer overflow that I’ve reported to Symantec in June 2013. The vulnerability impacts Symantec Endpoint Protection Manager (SEPM, a.k.a. the central SEP server) versions 12.1.0 to 12.1.2. Here are some references about the bug:

SEH-based approach

The PoC code (provided below), simply overwrite EIP by using a SEH-based technique. Unfortunately, due to memory protection mechanisms, I wasn’t able to create a stable exploit using this technique since all modules are compiled using the /SafeSEH flag and workarounds (that I knew) were found useless.

more here.......http://funoverip.net/2014/04/symantec-endpoint-protection-manager-cve-2013-1612-remote-buffer-overflow-poc/

Viewing all articles
Browse latest Browse all 8064

Trending Articles