Dislocker 0.7.3 及之前版本在 get_vmk() 和 get_fvek() 函数中存在整数下溢漏洞,攻击者可通过构造特定大小的数据项(datum sizes)触发越界堆内存读取。攻击者可以提供一个恶意的 BitLocker 卷镜像,其中数据项大小小于 36 字节的 AES-CCM 头部长度,从而导致 hexdump() 函数发生越界读取,并最终使 dislocker 程序崩溃。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet