vendor:
mIRC
by:
SkD
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: mIRC
Affected Version From: 6.34
Affected Version To: 6.34
Patch Exists: YES
Related CWE: N/A
CPE: a:mirc:mirc:6.34
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP3, Windows Vista SP0
2009
mIRC 6.34 Remote Buffer Overflow Exploit
A day's work of debugging and looking at mIRC revealed a buffer overflow vulnerability in mIRC 6.34. The exploit was tested on Windows XP SP3 English and Windows Vista SP0. The exploit uses a win32_exec payload to execute a calculator command. The exploit is triggered by sending a malicious payload to the server.
Mitigation:
Upgrade to the latest version of mIRC.