vendor:
Steamcast
by:
His0k4
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Steamcast
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP SP2
Steamcast Remote Buffer Overflow Exploit
This exploit takes advantage of a buffer overflow vulnerability in Steamcast's HTTP request handling. It is a SEH-based exploit that allows remote code execution. The exploit runs a shellcode that will be executed when the program is closed. It requires finding a DLL that is not compiled with GS (Stack Cookies) protection. The provided shellcode is the 'win32_adduser' payload from Metasploit, which creates a new user on the target system.
Mitigation:
The vendor should release a patch that fixes the buffer overflow vulnerability and compiles the affected DLL with GS protection. Users should update to the patched version as soon as it becomes available.