About this document
RPC Buffer Overflow in OLE VARIANT by Petro Bondar is a document available to read on EtoBox.
The document describes an integer overflow vulnerability in the RPC marshalling of OLE VARIANT data types. This allows triggering a heap buffer overflow by crafting VARIANT parameters with a total serialized size exceeding 32 bits. The vulnerability was used to achieve remote code execution in Microsoft Edge and local privilege escalation in the UPnP Host Service process.
- Author
- Petro Bondar
- Language
- EN