vendor:
Frigate 3
by:
Xenofon Vassilakopoulos
7.5
CVSS
HIGH
Buffer Overflow
CWE
Product Name: Frigate 3
Affected Version From: 3.36
Affected Version To: 3.36
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 7 Professional SP1 x86
2020
Frigate 3.36 – Buffer Overflow (SEH)
This exploit allows an attacker to execute arbitrary code on a system running Frigate 3.36. By generating a specially crafted 'test.txt' file and copying its contents to the clipboard, an attacker can trigger a buffer overflow when pasting the contents into Frigate3's 'Find Computer' feature. This results in the execution of the Windows calculator application.
Mitigation:
Apply the latest version of the software or vendor-supplied patch.