vendor:
Amaya
by:
Rob Carter
9.3
CVSS
HIGH
Stack Overflow
119
CWE
Product Name: Amaya
Affected Version From: Amaya 11
Affected Version To: Amaya 11
Patch Exists: YES
Related CWE: N/A
CPE: a:w3c:amaya:11
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows Vista SP1
2009
Amaya 11 bdo tag stack overflow
Amaya 11 bdo tag stack overflow is a vulnerability that allows an attacker to execute arbitrary code on the target system. The exploit bypasses safeSEH by jumping to a pop pop push pop ret sequence in one of the amaya modules that has a constant base address in memory. It then ret's back to the stack, short jump over the overwritten SEH, decodes the first 12 bytes of the shellcode and then runs the repaired shellcode to bind a shell on port 1337.
Mitigation:
Ensure that all software is up to date and patched with the latest security updates.