vendor:
Orbital Viewer
by:
Crazy_Hacker
7,8
CVSS
HIGH
Stack Overflow
121
CWE
Product Name: Orbital Viewer
Affected Version From: 1.04
Affected Version To: 1.04
Patch Exists: YES
Related CWE: N/A
CPE: a:orbitals:orbital_viewer:1.04
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: WinXp SP2
2010
Orbital Viewer v1.04 (.orb/.ov) Local Universal Stack Overflow Exploit [SEH]
This exploit is a local universal stack overflow exploit for Orbital Viewer v1.04 (.orb/.ov). It uses a universal pop ebx - pop eax - ret at 0x00457C03 [ov.exe] to gain control of the execution flow and then executes a shellcode to launch a calculator.
Mitigation:
The user should update to the latest version of Orbital Viewer v1.04 (.orb/.ov) to mitigate this vulnerability.