vendor:
QuickTime Player
by:
Krystian Kloskowski (h07) <h07@interia.pl>
7.5
CVSS
HIGH
SEH Overwrite
CWE
Product Name: QuickTime Player
Affected Version From: Apple QuickTime Player 7.3
Affected Version To: Unknown
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP SP2 Polish
Unknown
Apple QuickTime 7.3 RTSP Response 0day Remote SEH Overwrite PoC Exploit
This is a proof-of-concept exploit for a remote SEH overwrite vulnerability in Apple QuickTime 7.3. The vulnerability allows an attacker to overwrite the Structured Exception Handling (SEH) chain, leading to arbitrary code execution.
Mitigation:
Apply the latest security patches from Apple. Upgrade to a newer version of QuickTime if possible.