Executive brief
RGui is a graphical interface for the R statistical computing environment. A security flaw in version 3.5.0 allows a local user to execute unauthorized commands on a computer by entering specially crafted text into the application's preference settings. This could lead to a full system compromise, data theft, or the installation of malicious software.
Technical details
A stack-based buffer overflow exists in RGui 3.5.0 within the 'GUI preferences' dialog. Specifically, the 'Language for menus and messages' field does not properly validate the length of input strings. A local attacker can exploit this by providing a long, malicious string that overwrites the Structured Exception Handler (SEH). By utilizing a Return-Oriented Programming (ROP) chain to call VirtualAlloc, an attacker can bypass Data Execution Prevention (DEP) and achieve arbitrary code execution. This issue was reportedly fixed in version 3.5.1.
Affected products
- The R Project for Statistical Computing RGui 3.5.0
Timeline
- 2018-09-01: other: Vulnerability discovered
- 2019-01-10: disclosed: Exploit published on Exploit-DB
- 2026-04-12: advisory: NVD/VulnCheck advisory published