vendor:
KeyWorks KeyHelp Module
by:
Nine:Situations:Group::pyrokinesis
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: KeyWorks KeyHelp Module
Affected Version From: 1.2.0312
Affected Version To: 1.2.0312
Patch Exists: Yes
Related CWE: N/A
CPE: a:emc:keyworks_keyhelp_module:1.2.312
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP3
2009
EMC multiple products KeyWorks KeyHelp Module (keyhelp.ocx 1.2.312) remote buffer overflow exploit (ie8 xp sp3)
The JumpMaddID() and JumpURL() methods of the KeyHelp.ocx 1.2.312 module of EMC multiple products suffer from a stack-based buffer overflow vulnerability. The EIP is overwritten after 537 bytes through the second argument, allowing attackers to execute arbitrary code. The exploit code provided in the text is a VBScript that executes calc.exe.
Mitigation:
Update to the latest version of the KeyHelp.ocx module.