vendor:
Gold Player
by:
Vivek Mahajan - C3p70r
5.5
CVSS
MEDIUM
Local Exploit
CWE
Product Name: Gold Player
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 8.1 Pro, Windows 7 Ultimate
2015
GOLD PLAYER Local Exploit
This exploit allows an attacker to create a file called buffer.txt, open it in the Gold Player application, and gain control of a bind tcp port at 4444. The exploit involves executing a Python script, copying the contents of buffer.txt, and pasting them into the Gold Player application. The exploit has been tested on Windows 8.1 Pro and Windows 7 Ultimate.
Mitigation:
Apply the latest patch or update to the Gold Player application.