vendor:
Adrenalin Player
by:
onying
N/A
CVSS
HIGH
SEH Buffer Overflow
119
CWE
Product Name: Adrenalin Player
Affected Version From: 2.2.5.3
Affected Version To: 2.2.5.3
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP SP3
2013
Adrenalin Player (.asx) – SEH Buffer Overflow
The exploit takes advantage of a buffer overflow vulnerability in Adrenalin Player. By sending a specially crafted .asx file, an attacker can overwrite the Structured Exception Handler (SEH) and gain control of the program execution flow. This exploit has been tested on Adrenalin Player version 2.2.5.3 running on Windows XP SP3.
Mitigation:
Update to the latest version of Adrenalin Player. Avoid opening .asx files from untrusted sources.