vendor:
IrfanView
by:
Unknown
7.5
CVSS
HIGH
Buffer Overflow
CWE
Product Name: IrfanView
Affected Version From: 3.99
Affected Version To: 3.99
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP SP2 French, Windows XP SP2 Portuguese, Windows XP SP2 English
IrfanView 3.99 .ANI File Buffer Overflow (Multiple Targets and port bind shell)
This exploit is for IrfanView 3.99 .ANI file buffer overflow vulnerability. It allows an attacker to execute arbitrary code by crafting a malicious .ANI file. The exploit also includes a bind shell payload that opens a TCP port 4444.
Mitigation:
Unknown