lang:

C++

regex:

CreateProcess\s?\(\s?NULL\s?,

description:

If the first parameter of CreateProcess is NULL then an unintended executable could be loaded, if the path for the intended executable has spaces and is not quoted correctly. See security remarks at: http://msdn.microsoft.com/en-us/library/windows/desktop/ms682425(v=vs.85).aspx
tags:
executable load injection
results