vendor:
Quick Player
by:
Abhishek Lyall and Puneet Jain
7.5
CVSS
HIGH
SEH Exploit
CWE
Product Name: Quick Player
Affected Version From: Quick Player 1.3
Affected Version To: Quick Player 1.3
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP SP2
Quick Player 1.3 Unicode SEH Exploit
This exploit takes advantage of a vulnerability in Quick Player 1.3 to execute arbitrary code. The exploit uses a unicode SEH overwrite technique to hijack the program flow and execute a shellcode that opens the calculator. The vulnerable version of Quick Player is 1.3 and it has been tested on Windows XP SP2.
Mitigation:
Update Quick Player to a non-vulnerable version.