Unpatched Microsoft Zero-Day in JET Allows Remote Code-Execution
#1
Quote:According to the Zero Day Initiative (ZDI), the flaw is an out-of-bounds (OOB) write in the Microsoft JET Database Engine, which underlies the Microsoft Access and Visual Basic software; it’s a less well-known alternative to Microsoft’s flagship SQL Server.

According to ZDI, the specific flaw exists within the management of indexes in JET. It can be triggered by opening a booby-trapped JET database file via OLEDB, which is an API designed by Microsoft that enables data to be accessed from an array of disparate sources in a uniform manner.  That consequently would cause a “write past the end of an allocated buffer,” i.e., a crash, which in turn would allow an adversary to execute code with the same privileges as the target machine’s legitimate user.

The good news is that exploiting the flaw would take some social engineering; the target would need to be coaxed to open a specially crafted file containing malicious data stored in the JET database format (and ZDI pointed out in its advisory on Thursday that various applications use that format). Adversaries could also trigger an exploit with a weaponized web page, according to ZDI

Source: https://threatpost.com/unpatched-microso...on/137597/
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Opera 124.0.5705.65
New update to Oper...harlan4096 — 09:20
Vivaldi 7.7 Build 3851.56
Vivaldi 7.7 Build ...harlan4096 — 09:19
Rest in Peace Windows? Large YouTube cha...
Is Linux an altern...harlan4096 — 09:18
XYplorer
XYplorer ver 28.00 (...damien76 — 17:05
uBlock Origin 1.68.0 (already available ...
uBlock Origin 1.68...harlan4096 — 12:10

[-]
Birthdays
Today's Birthdays
No birthdays today.
Upcoming Birthdays
No upcoming birthdays.

[-]
Online Staff
harlan4096's profile harlan4096
Administrator

>