vendor:
DVD X Player 5.5 Pro
by:
Blake
7,8
CVSS
HIGH
SEH Overwrite
119
CWE
Product Name: DVD X Player 5.5 Pro
Affected Version From: 5.5 Pro
Affected Version To: 5.5 Pro
Patch Exists: YES
Related CWE: N/A
CPE: a:dvd-x-player:dvd_x_player_5.5_pro
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2020
DVD X Player 5.5 Pro Buffer Overflow
DVD X Player 5.5 Pro is vulnerable to a buffer overflow vulnerability when a long string of data is sent to the application. This can be exploited to execute arbitrary code by overwriting the SEH handler with a pointer to the malicious code. Bypassing ASLR is possible by using a non-ASLR enabled module. Egghunter is not needed as there is at least 2000 bytes for shellcode.
Mitigation:
Update to the latest version of DVD X Player 5.5 Pro