vendor:
Ace Player HD
by:
Gjoko 'LiquidWorm' Krstic
7,5
CVSS
HIGH
Format String Vulnerability
134
CWE
Product Name: Ace Player HD
Affected Version From: 2.1.9
Affected Version To: 2.1.9
Patch Exists: Yes
Related CWE: N/A
CPE: a:acestream:ace_player_hd:2.1.9
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Microsoft Windows 7 Professional SP1 (EN) 64bit
2013
ACE Stream Media 2.1 (acestream://) Format String Exploit PoC
Ace Stream Media (Ace Player HD) is prone to a remote format string vulnerability because the application fails to properly sanitize user-supplied input thru the URI using the 'acestream://' protocol before including it in the format-specifier argument of a formatted-printing function. A remote attacker may exploit this issue to execute arbitrary code with the privileges of the user running the affected application and/or cause memory address disclosure. Failed exploit attempts may cause denial-of-service (DoS) conditions.
Mitigation:
Update to the latest version of Ace Stream Media (Ace Player HD) or apply the patch provided by the vendor.