Skip to content

Opening book details…

About this document

RPC Buffer Overflow in OLE VARIANT by Petro Bondar is a document available to read on EtoBox.

The document describes an integer overflow vulnerability in the RPC marshalling of OLE VARIANT data types. This allows triggering a heap buffer overflow by crafting VARIANT parameters with a total serialized size exceeding 32 bits. The vulnerability was used to achieve remote code execution in Microsoft Edge and local privilege escalation in the UPnP Host Service process.

Author
Petro Bondar
Language
EN