vendor:
ProShow
by:
Yonatan_Correa
9.3
CVSS
HIGH
Local Exploit
N/A
CWE
Product Name: ProShow
Affected Version From: v9.0.3797
Affected Version To: v9.0.3797
Patch Exists: YES
Related CWE: N/A
CPE: a:photodex:proshow
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 7
2019
ProShow v9.0.3797 Local Exploit
ProShow v9.0.3797 is vulnerable to a local exploit which allows an attacker to execute arbitrary code on the target system. The exploit involves creating a file called 'load' and copying it to the ProShow Producer directory. When the ProShow.exe is executed, the malicious code is executed and a connection is established with the attacker's machine on port 4444.
Mitigation:
Update to the latest version of ProShow.