Integer Overflow Vulnerability in Capstone Product by Capstone
CVE-2017-6952
8.8HIGH
What is CVE-2017-6952?
An integer overflow vulnerability exists in the cs_winkernel_malloc function located in winkernel_mm.c, affecting Capstone versions up to 3.0.4. This flaw can enable attackers to exploit the system, leading to a denial of service due to a heap-based buffer overflow within a kernel driver when a large value is provided. The vulnerability may also result in additional unspecified impacts, emphasizing the critical need for updates and patches.
