vendor:
Crystal Player
by:
Arham Muhammad
7.5
CVSS
HIGH
Local Buffer Overflow
CWE
Product Name: Crystal Player
Affected Version From: 1.98
Affected Version To: 1.98
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows
Crystal Player 1.98 Playlist(.mls) File Local Buffer Overflow Exploit
The exploit creates a crafted .mls file which triggers a buffer overflow in Crystal Player 1.98. This vulnerability allows an attacker to overwrite the EIP and EBP registers, leading to a Denial of Service (DOS) and potential library destruction upon successful exploitation. The exploit adds a user 'root' with password 'root' to the operating system. It has been tested on x86 Vista Enterprise Edition.