Infinite loop in GetSusp - CVE-2018-6687
Published: February 28, 2019
GetSusp
Detailed vulnerability description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation when processing data in GetFileVersionInfoW() function. A remote attacker can create a specially crafted file, which when analyzed, will trigger infinite loop and crash the application.