vendor:
ActFax Server
by:
chap0
9,3
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: ActFax Server
Affected Version From: 4.25, Build 0221 (2010-02-11)
Affected Version To: 4.25, Build 0221 (2010-02-11)
Patch Exists: YES
Related CWE: N/A
CPE: actfax_setup_en.exe
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP3
2011
ActFax Server (LPD/LPR) Remote Buffer Overflow Exploit
ActFax Server is vulnerable to a remote buffer overflow exploit. The exploit is triggered when a malicious payload is sent to the server via the LPD/LPR protocol. The payload contains an egghunter EDI encoded shellcode which is then executed on the vulnerable system. This exploit was discovered by chap0 in 2011 and affects ActFax Server version 4.25, Build 0221 (2010-02-11).
Mitigation:
The vendor has released a patch to address this vulnerability.