vendor:
ProShow Producer
by:
Mike Czumak
7.5
CVSS
HIGH
Local Buffer Overflow
119
CWE
Product Name: ProShow Producer
Affected Version From: 5.0.3256
Affected Version To: 5.0.3310
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP SP3
2013
Photodex ProShow Producer v5.0.3310 – Local Buffer Overflow (SEH)
This exploit targets a vulnerability in Photodex ProShow Producer v5.0.3310. It uses a jump to an offset of ESP instead of an egghunter. The seh exploit looks like this: shellcode-->junk-->next seh-->seh-->jumpcode. The exploit replaces a file in the app folder.
Mitigation:
Apply the latest patch or update to a non-vulnerable version.