E17-3dsz1
CVSS:
8.1 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
False Positive:
f
Variants:
3
Year:
2017
Description
This strike exploits a Heap-Based Buffer Overflow vulnerability in Microsoft Windows Dnsapi Library.
The vulnerability is due to improper handling of some fields in the NSEC3 resource record sent in response to a DNS request.
An attacker could remotely execute arbitrary code on a target system by sending a malicious DNS response.
CVE
References
https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2017-11779
Metasploit
http://www.zerodayinitiative.com/advisories/ZDI-17-846
Zdi
17-846