Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2017-5005 PoC — Quick Heal Internet Security、Total Security和AntiVirus Pro on OS X 缓冲区错误漏洞

Source
Associated Vulnerability
Title: Quick Heal Internet Security、Total Security和AntiVirus Pro on OS X 缓冲区错误漏洞 (CVE-2017-5005)
Description:Stack-based buffer overflow in Quick Heal Internet Security 10.1.0.316 and earlier, Total Security 10.1.0.316 and earlier, and AntiVirus Pro 10.1.0.316 and earlier on OS X allows remote attackers to execute arbitrary code via a crafted LC_UNIXTHREAD.cmdsize field in a Mach-O file that is mishandled during a Security Scan (aka Custom Scan) operation.
Description
CVE-2017-5005 for Quick Heal Antivirus
Readme
QuickHeal
=========
CVE-2017-5005 for Quick Heal Antivirus


Advisory
--------
**Improper Restriction of Operations** within the **Bounds of a Memory Buffer** vulnerability.

The software performs operations on a memory buffer, but it can read from or write to a memory location that is outside of the intended boundary of the buffer.


Vulnerability Description
-------------------------
We found that the **Quick Heal Internet Security** is vulnerable to **Out of Bound Write on Stack Buffer** due to improper validation of `LC_UNIXTHREAD.cmdsize` (**Mach-O**).

This vulnerability can be exploited to gain **Remote Code Execution** as well as **Privilege Escalation**.


Proof of Concept
----------------
[![Quick Heal Exploit Demo](https://img.youtube.com/vi/h9LOsv4XE00/0.jpg)](https://www.youtube.com/watch?v=h9LOsv4XE00)


Vendor
------
[http://www.quickheal.co.in/](http://www.quickheal.co.in/)


Products
--------
 * Quick Heal Internet Security 10.1.0.316 and prior
 * Quick Heal Total Security 10.1.0.316 and prior
 * Quick Heal AntiVirus Pro 10.1.0.316 and prior


Disclosure Timeline
-------------------
 * 09 June 2016 – Reported to vendor
 * 11 June 2016 – Received acknowledgement from vendor & Patch released


Author
------
> **Ashfaq Ansari**

> ashfaq[at]payatu[dot]com

> **[@HackSysTeam](https://twitter.com/HackSysTeam) | [Blog](http://hacksys.vfreaks.com/ "HackSys Team") | [null](http://null.co.in/profile/411-ashfaq-ansari)**

> ![Payatu Technologies](http://www.payatu.com/wp-content/uploads/2015/04/Payatu_Logo.png "Payatu Technologies Pvt. Ltd.")

> [http://www.payatu.com/](http://www.payatu.com/ "Payatu Technologies Pvt. Ltd.")


License
-------
Please see the file `LICENSE` for copying permission


------------------------------------------------------------------------
[http://hacksys.vfreaks.com](http://hacksys.vfreaks.com)

![HackSys Team](http://hacksys.vfreaks.com/wp-content/themes/Polished/images/logo.png)
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →