A forum for reverse engineering, OS internals and malware analysis 

Discussion on reverse-engineering and debugging.
 #8774  by Meriadoc
 Tue Sep 27, 2011 12:06 pm
GMER 1.0.15.15641 MFT Overwrite 0day

Public exploit-db.com, I have not tested.
Program : GMER (1.0.15.15641)
Homepage : gmer
Discovery : 2011/08/01
Author Contacted : 2011/08/09
Status of vuln : 0day
Found by : Heurs
This Advisory : Heurs
Contact : sleberreatnes.fr

//----- Description of vulnerability

GMER don't check all inputs addresses of an IOCTL.

nes.fr
ghostinthestack.org

sleberre at nes dot fr
heurs at ghostsinthestack dot org

Twitter : @NES_SecurityLab
@Heurs