vendor:
AtomixMP3
by:
His0k4
9.3
CVSS
HIGH
Universal Seh Overwrite Exploit
119
CWE
Product Name: AtomixMP3
Affected Version From: 2.3
Affected Version To: 2.3
Patch Exists: YES
Related CWE: N/A
CPE: a:atomix_mp3:atomixmp3
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2009
AtomixMP3 <= 2.3 (playlist) Universal Seh Overwrite Exploit
AtomixMP3 is vulnerable to a Universal Seh Overwrite Exploit. This exploit is triggered when a specially crafted .m3u file is opened. The payload is encoded with PexAlphaNum encoder and the exploit uses win32_exec to execute the payload. The payload contains a shellcode which executes calc.exe.
Mitigation:
Update to the latest version of AtomixMP3