Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2022-28882

Description

A Denial-of-Service (DoS) vulnerability was discovered in F-Secure & WithSecure products whereby the aegen.dll will go into an infinite loop when unpacking PE files. This eventually leads to scanning engine crash. The exploit can be triggered remotely by an attacker.

POC

Reference

No PoCs from references.

Github

- https://github.com/ARPSyndicate/cvemon

- https://github.com/Team-BT5/WinAFL-RDP

- https://github.com/bacon-tomato-spaghetti/WinAFL-RDP

- https://github.com/googleprojectzero/winafl

- https://github.com/ssumachai/CS182-Project

- https://github.com/yrime/WinAflCustomMutate