WorstFit: Unveiling Hidden Transformers in Windows ANSI!
(blog.orange.tw)
from tedu@inks.tedunangst.com to inks@inks.tedunangst.com on 10 Jan 14:54
https://inks.tedunangst.com/l/5161
from tedu@inks.tedunangst.com to inks@inks.tedunangst.com on 10 Jan 14:54
https://inks.tedunangst.com/l/5161
The research unveils a new attack surface in Windows by exploiting Best-Fit, an internal charset conversion feature. Through our work, we successfully transformed this feature into several practical attacks, including Path Traversal, Argument Injection, and even RCE, affecting numerous well-known applications!
#exploit #programming #security #text #turtles #windows
#exploit #inks #programming #security #text #turtles #windows
threaded - newest