vendor:
AdamView
by:
Muhamad Fadzil Ramli
7.5
CVSS
HIGH
SEH Buffer Overflow
119
CWE
Product Name: AdamView
Affected Version From: 4.30.003
Affected Version To: 4.30.003
Patch Exists: NO
Related CWE: CVE-2014-8386
CPE: advantech:adamview
Platforms Tested: Microsoft Windows XP SP3 EN
2014
Advantech AdamView (.gni) SEH Buffer Overflow
This exploit demonstrates a SEH (Structured Exception Handler) buffer overflow vulnerability in Advantech AdamView. By creating a specially crafted .gni file, an attacker can execute arbitrary code on a vulnerable system. The vulnerability was discovered by Daniel Kazimirow and Fernando Paez of Core Security. The exploit was developed by Muhamad Fadzil Ramli.
Mitigation:
Apply the vendor-supplied patch or upgrade to a non-vulnerable version of the software.