vendor:
Beyond Compare
by:
mr_me
9,3
CVSS
HIGH
Stack Buffer Overflow
119
CWE
Product Name: Beyond Compare
Affected Version From: 3.0.13 b9599
Affected Version To: 3.0.13 b9599
Patch Exists: Yes
Related CWE: N/A
CPE: a:scootersoftware:beyond_compare:3.0.13
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP sp3
2010
Beyond Compare 3.0.13 b9599 (.zip) 0day Stack Buffer Overflow PoC exploit
This is a proof-of-concept exploit for a stack buffer overflow vulnerability in Beyond Compare 3.0.13 b9599 (.zip). The vulnerability is triggered when a maliciously crafted .zip file is opened, which causes a buffer overflow and allows arbitrary code execution. The exploit code creates a malicious .zip file containing a shellcode and padding, which is then used to overwrite the SEH and NSEH registers.
Mitigation:
The vulnerability has been patched in the latest version of Beyond Compare, as well as in previous versions.