vendor:
SigPlus Pro
by:
mr_me - @StevenSeeley
7.5
CVSS
HIGH
Buffer Overflow
Not mentioned
CWE
Product Name: SigPlus Pro
Affected Version From: Not mentioned
Affected Version To: Not mentioned
Patch Exists: NO
Related CWE: Not mentioned
CPE: Not mentioned
Platforms Tested: Windows 7 Professional vN (IE8), Windows XP Professional SP3 (IE7/8)
Not mentioned
SigPlus Pro v3.74 ActiveX Signature Capture LCDWriteString() Remote BoF JIT Spray – aslr/dep bypass
The exploit involves spraying the JIT memory pages with nops + egghunter combined with a call to VirtualProtect() to mark the newly found shellcode as executable and then jumping to it. By spraying so many pages, the exploit becomes reliable working 9/10 times.
Mitigation:
The latest version of SigPlus Pro is not vulnerable. Users should update to the latest version to mitigate the risk of this exploit.