vendor:
DVDXPlayer
by:
Kevin Randall
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: DVDXPlayer
Affected Version From: 5.5 Pro
Affected Version To: 5.5 Pro
Patch Exists: NO
Related CWE:
CPE: a:dvd-x-player:dvdxplayer:5.5
Platforms Tested: Windows 7
2019
DVDXPlayer 5.5 Pro Local Buffer Overflow with SEH
This exploit takes advantage of a local buffer overflow vulnerability in DVDXPlayer 5.5 Pro. By sending a specially crafted payloadofficial.plf file, an attacker can trigger a buffer overflow and gain control of the SEH (Structured Exception Handling) chain. This allows the attacker to execute arbitrary code on the targeted system.
Mitigation:
To mitigate this vulnerability, users are advised to update to the latest version of DVDXPlayer and avoid opening suspicious or untrusted .plf files.