Buffer overflow in Sysinternals Process Explorer 9.23, and other versions before 9.25, allows local users to execute arbitrary code via a long CompanyName field in the VersionInfo information in a running process.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/14616 | vdb entry exploit |
http://securitytracker.com/id?1014742 | exploit vdb entry vendor advisory |
http://secunia.com/advisories/16525 | third party advisory |
http://www.sysinternals.com/Forum/forum_posts.asp?TID=957&PN=1 |