vendor:
HTML5 Video Player
by:
Dino Covotsos
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: HTML5 Video Player
Affected Version From: 1.2.2005
Affected Version To: 1.2.2005
Patch Exists: NO
Related CWE: TBC
CPE: html5videoplayer
Platforms Tested: Windows XP
2019
HTML5 Video Player 1.2.5 – Local Buffer Overflow – Non SEH
This exploit targets a buffer overflow vulnerability in HTML5 Video Player 1.2.5. By pasting a specially crafted payload into the 'KEY CODE' field under the 'Register' section of the application, an attacker can trigger a buffer overflow and execute arbitrary code. This exploit does not require SEH exploitation. The exact details of the vulnerability are yet to be determined by Mitre.
Mitigation:
To mitigate this vulnerability, it is recommended to update to a patched version of the HTML5 Video Player software. Alternatively, users can disable the affected feature or use a different video player software.