vendor:
                    Winmod
                by:
                    corelan - c0d3r
                7.5
                        CVSS
                    HIGH
                    Local Stack Overflow
                    Not provided
                        CWE
                    Product Name: Winmod
                    Affected Version From:  Winmod 1.4
                    Affected Version To:  Winmod 1.4
                    Patch Exists: No
                    Related CWE: Not provided
                    CPE:  Not provided
                    Platforms Tested:  Windows XP SP3 (en)
                    Not provided
                    Winmod 1.4 (.lst) Local Stack Overflow Exploit (RET overwrite+SEH)
This exploit targets the Winmod 1.4 (.lst) software on Windows XP SP3. It utilizes a stack overflow vulnerability to execute arbitrary code. The exploit overwrites the return address (RET) and structured exception handler (SEH) to gain control of the program. It then injects shellcode to execute a calculator application. The shellcode used in this exploit is based on the Metasploit framework.
Mitigation:
					No mitigation or remediation provided