vendor:
Easy File Sharing Web Server
by:
ch3rn0byl
7.5
CVSS
HIGH
SEH Overflow
CWE
Product Name: Easy File Sharing Web Server
Affected Version From: 7.2
Affected Version To: 7.2
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 7, 8, 8.1, 10
2016
Easy File Sharing Web Server 7.2 SEH Overflow with Egghunter
This exploit targets Easy File Sharing Web Server version 7.2 and leverages a SEH overflow vulnerability to execute arbitrary code. It also uses an egghunter technique to locate the payload in memory. The vulnerability allows an attacker to gain admin privileges on the targeted system. The exploit has been tested on Windows 7, 8, 8.1, and 10.
Mitigation:
Update to a patched version of Easy File Sharing Web Server.