CVE ID | CVE-2014-3802 |
CVSS SCORE | 6.8, AV:N/AC:M/Au:N/C:P/I:P/A:P |
AFFECTED VENDORS |
Microsoft |
AFFECTED PRODUCTS |
Debug Interface Access SDK |
VULNERABILITY DETAILS |
The specific flaw exists within the parsing of PDB files. The issue lies in a failure to sanitize a value which is then used in the calculation of an address for a dynamic call. An attacker can leverage this vulnerability to execute code under the context of the current process. |
ADDITIONAL DETAILS |
Microsoft has issued an update to correct this vulnerability. More details can be found at:
http://go.microsoft.com/fwlink/p/?LinkId=306566 |
DISCLOSURE TIMELINE |
|
CREDIT | 80ceb6400c43bd3fa9f1ef561f7c51d929fe0199 |