vendor:
DIZzy
by:
g30rg3_x
7,8
CVSS
HIGH
Stack Overflow
119
CWE
Product Name: DIZzy
Affected Version From: 1.12
Affected Version To: 1.12
Patch Exists: No
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP3 Eng/Spa
2010
DIZzy 1.12 Local Stack Overflow
DIZzy 1.12 is vulnerable to a local stack overflow vulnerability. The bug was originally found on 22/02/2010 but since there is no response from developers it goes public. An attacker can exploit this vulnerability by executing a specially crafted payload with a length of 284 NOPs followed by a JMP ESP address from MSCTF.dll and 17 NOPs followed by a 57-byte shellcode.
Mitigation:
Update to the latest version of DIZzy 1.12