vendor:
Unknown
by:
FoToZ
7.5
CVSS
HIGH
Buffer Overflow
Unknown
CWE
Product Name: Unknown
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE: Unknown
CPE: Unknown
Platforms Tested: Windows XP SP1
Unknown
GDI+ Buffer Overrun Exploit
This is a buffer overflow exploit in GDI+ that allows for the execution of arbitrary code. The exploit launches a local cmd.exe without being bound to the network. The shellcode used is provided in the code. The exploit has been tested on an unpatched Windows XP SP1 system.
Mitigation:
Unknown