In SweetScape 010 Editor 9.0.1, improper validation of arguments in the internal implementation of the Memcpy function (provided by the scripting engine) allows an attacker to overwrite arbitrary memory, which could lead to code execution.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://www.sweetscape.com/010editor/manual/ReleaseNotes.htm | release notes vendor advisory |
https://github.com/ereisr00/bagofbugz/blob/master/010Editor | third party advisory exploit |
https://ereisr00.github.io/ | third party advisory exploit |