[CVE-2016-0014] Executable installers are vulnerable^WEVIL (case 1): Microsoft's IExpress resp. WExtract, SFXCab, BoxStub, …

Posted by Stefan Kanthak on Jan 15

Hi @ll,

IExpress (<https://msdn.microsoft.com/en-us/library/dd346760.aspx>)
creates executable installers [°] or self-extracting archives for
Windows by embedding a .CAB archive and some strings as resources
into a copy of the program %SystemRoot%System32WExtract.exe.

These self-extracting archives/executable installers, especially
those made by Microsoft [‘] (available in the Microsoft download
center or distributed per Windows…