vendor:
FL Studio
by:
Dark-Puzzle (Souhail Hammou)
7,5
CVSS
HIGH
SEH Based Buffer Overflow
N/A
CWE
Product Name: FL Studio
Affected Version From: 10 Producer Edition
Affected Version To: 10 Producer Edition
Patch Exists: N/A
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7 64-bits
2012
FL Studio 10 Producer Edition – SEH Based Buffer Overflow PoC
Fl Studio is Prone to a SEH based Buffer Overflow which allows attacker to execute arbitary code on the victim's machine. To trigger the vulnerability the attacker must fake the 'Browser Extra search folder' path & paste the input released from this PoC. Looking a little bit deeper in the stack & in the EBP register we will see that the software will try to create a file named e.g. BBBBCCCC.NFO. Then the EIP is overwritten with the SEH address. The Exploit will look like this : [Junk 'A' x 416] [6 Bytes Jump + 2Nops ] [p/p/r address or other] [Shellcode].
Mitigation:
N/A