vendor:
Not provided
by:
Daniel Romero Perez (@daniel_rome)
7.5
CVSS
HIGH
The exploit is a stack buffer overflow vulnerability in MyMp3-Player software version 3.02.067. It allows an attacker to bypass DEP (Data Execution Prevention) and execute arbitrary code on the target system. The exploit uses a buffer of 1024 bytes and a shellcode that spawns a calculator. It also leverages ROP (Return-Oriented Programming) techniques to bypass […]
Not provided
CWE
Product Name: Not provided
Affected Version From: Not provided
Affected Version To: Not provided
Patch Exists: NO
Related CWE: Not provided
CPE: Not provided
Platforms Tested: Windows XP SP3 - ES
Not provided
MyMp3-Player ‘.m3u’ Stack BOF (Bypass DEP)
The exploit is a stack buffer overflow vulnerability in MyMp3-Player software version 3.02.067. It allows an attacker to bypass DEP (Data Execution Prevention) and execute arbitrary code on the target system. The exploit uses a buffer of 1024 bytes and a shellcode that spawns a calculator. It also leverages ROP (Return-Oriented Programming) techniques to bypass DEP using the SetProcessDEPPolicy function. The exploit has been tested on Windows XP SP3 - ES.
Mitigation:
No mitigation or remediation provided