Microsoft Windows Dnsapi.dll NSEC3 Buffer Overflow

Strike ID:
E17-3dsz1
CVSS:
8.1 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
False Positive:
f
Variants:
3
Year:
2017

Description

This strike exploits a Heap-Based Buffer Overflow vulnerability in Microsoft Windows Dnsapi Library. The vulnerability is due to improper handling of some fields in the NSEC3 resource record sent in response to a DNS request. An attacker could remotely execute arbitrary code on a target system by sending a malicious DNS response.

CVE

References

Metasploit

Zdi

Bid