vendor:
Eudora
by:
Krystian Kloskowski (h07)
7.5
CVSS
HIGH
Remote SEH Overwrite
CWE
Product Name: Eudora
Affected Version From: Eudora 7.1.0.9
Affected Version To: Eudora 7.1.0.9
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 2000 SP4 Polish
Eudora 7.1 (IMAP FLAGS) 0day Remote SEH Overwrite PoC Exploit
This is a proof-of-concept exploit for a remote SEH overwrite vulnerability in Eudora 7.1. The vulnerability was discovered by Krystian Kloskowski (h07) and allows an attacker to execute arbitrary code on the target system. The exploit targets the IMAP FLAGS command and uses a Windows Execute Command shellcode to spawn the calculator (calc.exe).
Mitigation:
Apply the latest patches and updates for Eudora to fix the vulnerability. Avoid opening emails or attachments from untrusted sources.