Jump to content
Aerosol

Microsoft Windows Text Services Memory Corruption (MS15-020)

Recommended Posts

Posted

#####################################################################################

Application: Microsoft Windows Text Services memory corruption.

Platforms: Windows

Versions: list.

Microsoft: MS15-020

Secunia: SA63220

{PRL}: 2015-03

Author: Francis Provencher (Protek Research Lab’s)

Website: http://www.protekresearchlab.com/

Twitter: @protekResearch

#####################################################################################

1) Introduction
2) Report Timeline
3) Technical details
4) POC

#####################################################################################

===============
1) Introduction
===============



Microsoft Corporation is an American multinational corporation headquartered in Redmond, Washington, that develops, manufactures, licenses, supports and sells computer software, consumer electronics and personal computers and services. Its best known software products are the Microsoft Windowsline of operating systems, Microsoft Office office suite, and Internet Explorer web browser. Its flagship hardware products are the Xbox game consoles and the Microsoft Surface tablet lineup. It is the world’s largest software maker measured by revenues.[5]It is also one of the world’s most valuable companies.[6]

([url]http://en.wikipedia.org/wiki/Microsoft[/url])

#####################################################################################

============================
2) Report Timeline
============================

2015-02-08: Francis Provencher from Protek Research Lab’s found the issue;
2015-03-04: MSRC confirmed the issue;
2015-03-10: Microsoft fixed the issue;
2015-03-10: Microsoft release a Patch for this issue.

#####################################################################################

============================
3) Technical details
============================

An unspecified error in Windows Text Services can be exploited to cause memory corruption..

#####################################################################################

===========

4) POC

===========

This file need to be open in wordpad.

[url]http://protekresearchlab.com/exploits/PRL-2015-03.rar[/url]
[url]http://www.exploit-db.com/sploits/36336.rar[/url]

###############################################################################
Search for:

Source

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...