vendor:
                    XAMPP
                by:
                    Talson
                6.1
                        CVSS
                    HIGH
                    Buffer Overflow
                    119
                        CWE
                    Product Name: XAMPP
                    Affected Version From:  3.3.2000
                    Affected Version To:  3.3.2000
                    Patch Exists: NO
                    Related CWE: CVE-2023-46517
                    CPE:  a:apachefriends:xampp:3.3.0
                    Platforms Tested:  Windows 11
                    2023
                    XAMPP v3.3.0 Buffer Overflow (Unicode + SEH)
The exploit involves running a Python script that creates a malicious file 'xampp-control.ini' which triggers a buffer overflow in XAMPP v3.3.0 when the application 'xampp-control.exe' is opened. By clicking on the 'admin' button for the Apache service, the exploit can be triggered, leading to potential code execution.
Mitigation:
					To mitigate this vulnerability, users should update to a patched version of XAMPP and avoid opening files from untrusted sources.