vendor:
IconLover
by:
cor3sm4sh3r
7,5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: IconLover
Affected Version From: 5.42
Affected Version To: 5.45
Patch Exists: YES
Related CWE: N/A
CPE: a:aha-soft:iconlover
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP Professional SP2
2015
IconLover v5.42 Buffer Overflow Exploit
A buffer overflow vulnerability exists in IconLover v5.42 and v5.45. An attacker can exploit this vulnerability by copying the content of exploit.txt to the clipboard, running the IconLover.exe software, clicking the File -> New Icon Lybrary option, clicking the Lybrary and pushing the Download button, pasting the input Website Adress (URL) AAAA+... string, clicking ok and hiding. Successful exploitation will open an instance of calc.exe.
Mitigation:
Upgrade to the latest version of IconLover.