vendor:
GetGo Download Manager
by:
bzyo
7.5
CVSS
HIGH
Remote Buffer Overflow (SEH)
CWE
Product Name: GetGo Download Manager
Affected Version From: 5.3.0.2712
Affected Version To: 5.3.0.2712
Patch Exists: NO
Related CWE:
CPE: a:getgo:download_manager:5.3.0.2712
Platforms Tested: Windows XP SP3
2018
GetGo Download Manager 5.3.0.2712 – Remote Buffer Overflow (SEH)
The exploit allows an attacker to remotely trigger a buffer overflow vulnerability in GetGo Download Manager 5.3.0.2712, leading to potential remote code execution on the victim's machine. By setting up a listener on port 443 and running the provided script on the attacking machine, the attacker can open the vulnerable application on the victim's machine and exploit the buffer overflow to gain a remote shell.
Mitigation:
The vendor should release a patch to fix the buffer overflow vulnerability in GetGo Download Manager 5.3.0.2712. In the meantime, users are advised to avoid downloading files from untrusted sources or to use an alternative download manager.