vendor:
X360 VideoPlayer ActiveX Control
by:
Rh0
7.5
CVSS
HIGH
Buffer Overflow in Data Section
N/A
CWE
Product Name: X360 VideoPlayer ActiveX Control
Affected Version From: 2.6
Affected Version To: 2.6
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Internet Explorer 10 32-bit (Windows 7 64-bit in VirtualBox)
2015
X360 VideoPlayer ActiveX Control RCE Full ASLR & DEP Bypass
When passing an overlong string to the ActiveX object's 'SetText' method, a buffer overflow in the data section occurs. It allows overwriting a subsequent pointer that can be used in a controlled memcpy when dispatching the object's 'SetFontName' method. With this arbitrary write, array structures can be manipulated to gain access to complete process memory. Equipped with this capability, necessary information can be leaked and manipulated to execute arbitrary code remotely.
Mitigation:
N/A