vendor:
CoolPlayer (Standalone)
by:
Charley Celice (stmerry)
7,5
CVSS
HIGH
Stack Overflow
119
CWE
Product Name: CoolPlayer (Standalone)
Affected Version From: 2.19
Affected Version To: 2.19
Patch Exists: YES
Related CWE: N/A
CPE: a:coolplayer:coolplayer:2.19
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP3 EN
2016
CoolPlayer (Standalone) build 2.19 – .m3u Stack Overflow
CoolPlayer (Standalone) build 2.19 is vulnerable to a stack overflow vulnerability. An attacker can exploit this vulnerability by crafting a malicious .m3u file and sending it to the target user. When the target user opens the malicious file, the attacker can overwrite the EIP and point to ESP (iertutil.dll) to execute shellcode (calc.exe).
Mitigation:
Upgrade to the latest version of CoolPlayer (Standalone) build 2.19.