header-logo
Suggest Exploit
vendor:
Prime95
by:
Achilles
7.5
CVSS
HIGH
Buffer Overflow (SEH)
119
CWE
Product Name: Prime95
Affected Version From: 29.8 build 6
Affected Version To: 29.8 build 6
Patch Exists: NO
Related CWE: Not provided
CPE: a:prime95:prime95:29.8:build:6
Metasploit:
Other Scripts:
Platforms Tested: Windows 7 x64
2019

Prime95 Version 29.8 build 6 – Buffer Overflow (SEH)

The Prime95 software version 29.8 build 6 is vulnerable to a buffer overflow (SEH) vulnerability. By running a python code, an attacker can exploit this vulnerability to gain unauthorized access to the system and execute arbitrary code. The exploit involves opening a malicious file, copying its content to the clipboard, and then pasting it into specific fields within the Prime95.exe application. This results in the creation of a bind shell on port 3110, providing the attacker with a remote command execution capability. The vulnerability is present in the libhwloc-15.dll library. The exploit code includes shellcode generated using msfvenom, which ensures compatibility with the Windows platform and avoids certain characters that may cause issues. The exploit has been tested on Windows 7 x64.

Mitigation:

To mitigate this vulnerability, users should update to a patched version of Prime95 that addresses the buffer overflow issue. Additionally, it is recommended to exercise caution when opening files from untrusted sources.
Source

Exploit-DB raw data: