Learning path

Full curriculum

Full curriculum

Unit content

Memory corruption and control-flow hijacking

Some memory-corruption vulnerabilities let an attacker modify data that later influences where the program executes.

A classic example is a stack buffer overflow that overwrites adjacent control data. More generally, corrupted function pointers, object metadata or return addresses can redirect control flow.

The attacker's goal need not be to inject a complete new program. Existing executable code can sometimes be chained or invoked with attacker-controlled data.

Successful exploitation therefore depends on more than the original out-of-bounds write. The attacker must understand which memory can be influenced, how corrupted values are later interpreted, and what execution paths remain available.

This distinction matters: memory corruption is the underlying violation, while control-flow hijacking is one possible consequence. The same memory-safety bug might instead leak data, crash the process or corrupt an authorization decision.