vendor:
Simple Startup Manager
by:
PovlTekstTV
N/A
CVSS
HIGH
Local Buffer Overflow
CWE
Product Name: Simple Startup Manager
Affected Version From: 1.17
Affected Version To: 1.17
Patch Exists: NO
Related CWE:
CPE: a:simple_startup_manager:1.17
Platforms Tested: Windows 7 Ultimate Service Pack 1 (32 and 64 bit)
2020
Simple Startup Manager 1.17 – ‘File’ Local Buffer Overflow (PoC)
The exploit takes advantage of a local buffer overflow vulnerability in Simple Startup Manager version 1.17. By exploiting this vulnerability, an attacker can execute arbitrary code on the target system. The exploit has been tested on Windows 7 Ultimate Service Pack 1 (32 and 64 bit) with DEP and ASLR disabled. The exploit requires space for shellcode of size 264.
Mitigation:
To mitigate this vulnerability, users are advised to update to a patched version of Simple Startup Manager or use an alternative startup manager software.