vendor:
VLC
by:
Muris Kurgas and Matteo Memelli
7.5
CVSS
HIGH
Double Sh311 Universal Exploit
119
CWE
Product Name: VLC
Affected Version From: VLC 0.8.6d
Affected Version To: VLC 0.8.6d
Patch Exists: YES
Related CWE: CVE-2007-6681
CPE: a:videolan:vlc:0.8.6d
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2007
VLC 0.8.6d Double Sh311 Universal Exploit
VLC 0.8.6d is vulnerable to a double sh311 universal exploit. This exploit allows an attacker to gain remote code execution on the vulnerable system. The vulnerability was discovered by Michal Luczaj and was coded by Muris Kurgas and Matteo Memelli. The exploit uses a win32_bind shellcode to gain remote code execution.
Mitigation:
Upgrade to the latest version of VLC 0.8.6d