SmadAV antivirus 9.1 is susceptible to null pointer exploitation. The application does not properly filter the scanner input that processed into smadengine.dll. The successful exploitation of this vulnerability could potentially result a crash on the application, since it will refer to a null pointer, EAX = 0000000

Metasploit has released DLLHijackAuditKit v2 to determine DLL vulnerabilities that still existing in the wild. This tool will scan possible DLL vulnerability and log the result to CSV file. DLLHijackAuditKit v2 can also make a PoC (will try to hijack the DLL and running calc.exe, of course this is optional) to be sent to the […]