SafeBreach-Labs/MagicDot

SafeBreach-Labs/MagicDot

Releases0
Stars98
A set of rootkit-like abilities for unprivileged users, and vulnerabilities based on the DOT-to-NT path conversion known issue

CVE History

CVEPublishedCVSS v3CVSS v2
4.2 MEDIUM

Process Explorer before 17.04 allows attackers to make it functionally unavailable (a denial of service for analysis) by renaming an executable file to a new extensionless 255-character name and launching it with NtCreateUserProcess. This can occur through an issue in wcscat_s error handling.