vendor:
DVD X Player 5.5 Professional
by:
D3r K0n!G
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: DVD X Player 5.5 Professional
Affected Version From: 5.5
Affected Version To: 5.5
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP SP3
2011
DVD X Player 5.5 Professional (.plf) Universal Buffer Overflow
The DVD X Player 5.5 Professional software is vulnerable to a buffer overflow attack. By crafting a specially formatted .plf file, an attacker can overwrite the program's memory and potentially execute arbitrary code. This exploit takes advantage of a JMP ESP instruction in the EchoDelayProcess.dll module to redirect program execution to the attacker's shellcode. The shellcode used in this exploit launches the Windows calculator application.
Mitigation:
To mitigate this vulnerability, users should update to the latest version of DVD X Player and exercise caution when opening files from untrusted sources.