vendor:
ASX to MP3 Converter
by:
Hazem Mofeed
9,3
CVSS
HIGH
Stack Overflow
121
CWE
Product Name: ASX to MP3 Converter
Affected Version From: 3.0.0.100
Affected Version To: 3.0.0.100
Patch Exists: YES
Related CWE: N/A
CPE: a:asx_to_mp3_converter:asx_to_mp3_converter:3.0.0.100
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP Home Edition SP3
2009
ASX to MP3 Converter Version 3.0.0.100 => Local stack overflow exploit
ASX to MP3 Converter Version 3.0.0.100 is vulnerable to a local stack overflow exploit. The vulnerability is triggered when a maliciously crafted .asx file is opened, which can lead to arbitrary code execution. The exploit code builds a malicious .asx file containing a shellcode and a return address, which is then used to overwrite the stack and execute the shellcode.
Mitigation:
The vendor has released a patch to address this vulnerability.