CWE-123

Write-what-where Condition

High

Description

Any condition where the attacker has the ability to write an arbitrary value to an arbitrary location, often as the result of a buffer overflow.

Potential Impact

How to Fix

Architecture and Design

Use a language that provides appropriate memory abstractions.

Operation

Use OS-level preventative functionality integrated after the fact. Not a complete solution.

Detection Methods

Related Weaknesses

References

View on MITRE CWE Database →

Need Help Fixing This Vulnerability?

Our security experts can help you identify and remediate CWE-123 vulnerabilities in your codebase.

Get Security Assessment