Static Code Analysis : fix non-absolute DLL/process loads that can be hijacked (Microsoft Security Advisory 2269637).

This commit is contained in:
Mounir IDRASSI committed 2014-11-08 23:20:35 +01:00
1 parent d6817f941a
commit f67748ae8e
5 files changed
+66 -11

No files matched your search

+11 -1
View File
@@ -795,10 +795,20 @@ BOOLEAN __stdcall FormatExCallback (int command, DWORD subCommand, PVOID paramet
BOOL FormatNtfs (int driveNo, int clusterSize)
{
char dllPath[MAX_PATH] = {0};
WCHAR dir[8] = { (WCHAR) driveNo + 'A', 0 };
PFORMATEX FormatEx;
HMODULE hModule = LoadLibrary ("fmifs.dll");
HMODULE hModule;
int i;
if (GetSystemDirectory (dllPath, MAX_PATH))
{
strcat(dllPath, "\\fmifs.dll");
}
else
strcpy(dllPath, "C:\\Windows\\System32\\fmifs.dll");
hModule = LoadLibrary (dllPath);
if (hModule == NULL)
return FALSE;