CVE-2023-42757

Process Explorer before 17.04 allows attackers to make it functionally unavailable (a denial of service for analysis) by renaming an executable file to a new extensionless 255-character name and launching it with NtCreateUserProcess. This can occur through an issue in wcscat_s error handling.
Configurations

No configuration.

History

26 Mar 2025, 21:15

Type Values Removed Values Added
CWE CWE-120

21 Nov 2024, 08:23

Type Values Removed Values Added
References () https://github.com/SafeBreach-Labs/MagicDot - () https://github.com/SafeBreach-Labs/MagicDot -
References () https://www.blackhat.com/asia-24/briefings/schedule/#magicdot-a-hackers-magic-show-of-disappearing-dots-and-spaces-36561 - () https://www.blackhat.com/asia-24/briefings/schedule/#magicdot-a-hackers-magic-show-of-disappearing-dots-and-spaces-36561 -
References () https://www.safebreach.com/blog/magicdot-a-hackers-magic-show-of-disappearing-dots-and-spaces/ - () https://www.safebreach.com/blog/magicdot-a-hackers-magic-show-of-disappearing-dots-and-spaces/ -

03 Jul 2024, 01:41

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.2
Summary
  • (es) Process Explorer anterior a 17.04 permite a los atacantes hacerlo funcionalmente no disponible (una denegación de servicio para análisis) cambiando el nombre de un archivo ejecutable a un nuevo nombre sin extensión de 255 caracteres y ejecutándolo con NtCreateUserProcess. Esto puede ocurrir debido a un problema en el manejo de errores de wcscat_s.

07 May 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-07 18:15

Updated : 2025-03-26 21:15


NVD link : CVE-2023-42757

Mitre link : CVE-2023-42757

CVE.ORG link : CVE-2023-42757


JSON object : View

Products Affected

No product.

CWE
CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')