Aerosol Posted March 12, 2015 Report Posted March 12, 2015 #####################################################################################Application: Microsoft Windows Text Services memory corruption.Platforms: WindowsVersions: list.Microsoft: MS15-020Secunia: SA63220{PRL}: 2015-03Author: Francis Provencher (Protek Research Lab’s)Website: http://www.protekresearchlab.com/Twitter: @protekResearch#####################################################################################1) Introduction2) Report Timeline3) Technical details4) POC#####################################################################################===============1) Introduction===============Microsoft Corporation is an American multinational corporation headquartered in Redmond, Washington, that develops, manufactures, licenses, supports and sells computer software, consumer electronics and personal computers and services. Its best known software products are the Microsoft Windowsline of operating systems, Microsoft Office office suite, and Internet Explorer web browser. Its flagship hardware products are the Xbox game consoles and the Microsoft Surface tablet lineup. It is the world’s largest software maker measured by revenues.[5]It is also one of the world’s most valuable companies.[6]([url]http://en.wikipedia.org/wiki/Microsoft[/url])#####################################################################################============================2) Report Timeline============================2015-02-08: Francis Provencher from Protek Research Lab’s found the issue;2015-03-04: MSRC confirmed the issue;2015-03-10: Microsoft fixed the issue;2015-03-10: Microsoft release a Patch for this issue.#####################################################################################============================3) Technical details============================An unspecified error in Windows Text Services can be exploited to cause memory corruption..#####################################################################################===========4) POC===========This file need to be open in wordpad.[url]http://protekresearchlab.com/exploits/PRL-2015-03.rar[/url][url]http://www.exploit-db.com/sploits/36336.rar[/url]###############################################################################Search for:Source Quote