vendor:
ALLMediaServer
by:
Mario Kartone Ciccarelli
9.8
CVSS
CRITICAL
Stack Buffer Overflow
121
CWE
Product Name: ALLMediaServer
Affected Version From: 0.95
Affected Version To: 0.95
Patch Exists: NO
Related CWE: CVE-2017-17932
CPE: a:allmediaserver:allmediaserver:0.95
Platforms Tested: Windows 7 x64 Ultimate Eng SP1
2018
Stack Buffer Overflow in ALLMediaServer 0.95
This exploit demonstrates a stack buffer overflow vulnerability in ALLMediaServer version 0.95. By sending a specially crafted request, an attacker can trigger a buffer overflow and potentially execute arbitrary code on the target system.
Mitigation:
The vendor should release a patch to fix the buffer overflow vulnerability. In the meantime, users should avoid using the affected version of the software or implement network-level defenses to block malicious requests.