vendor:
Hex Workshop
by:
Security^Ghost and DATA_SNIPER
9.3
CVSS
HIGH
Local Code Execution
78 (Improper Neutralization of Special Elements used in an OS Command)
CWE
Product Name: Hex Workshop
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP2 FR
2009
Hex Workshop <= v6 (.hex) File Local Code Execution
Hex Workshop is vulnerable to a local code execution vulnerability. An attacker can exploit this vulnerability by creating a specially crafted .hex file and importing it into Hex Workshop. This will cause the application to execute arbitrary code on the system.
Mitigation:
Users should avoid opening untrusted .hex files in Hex Workshop.