vendor:
DVD X Player
by:
sickness
7.5
CVSS
HIGH
DEP + ASLR Bypass
CWE
Product Name: DVD X Player
Affected Version From: DVD X Player 5.5 Professional
Affected Version To: DVD X Player 5.5 Professional
Patch Exists: NO
Related CWE:
CPE: a:dvd-x-player:dvd_x_player:5.5
Platforms Tested: Windows XP SP2, Windows XP SP3, Windows 7
2011
DVD X Player 5.5 Professional (.plf) Universal DEP + ASLR BYPASS
This exploit bypasses Data Execution Prevention (DEP) and Address Space Layout Randomization (ASLR) in DVD X Player 5.5 Professional (.plf) file. It allows arbitrary code execution.
Mitigation:
Update to a patched version of DVD X Player 5.5 Professional