vendor:
Net Resource ActiveX
by:
dookie
7.5
CVSS
HIGH
SEH Exploit
CWE
Product Name: Net Resource ActiveX
Affected Version From: 4.0.0.5
Affected Version To: 4.0.0.5
Patch Exists: NO
Related CWE:
CPE: SKNETRESOURCELib.SKNetResource
Platforms Tested:
Magneto Software Net Resource ActiveX v4.0.0.5 NetFileClose SEH Exploit (Universal)
This exploit targets the Magneto Software Net Resource ActiveX v4.0.0.5 NetFileClose function, allowing arbitrary code execution. The exploit uses a shellcode to execute the calc.exe command.
Mitigation:
Apply the latest patch from the vendor.